Skip to content

@google-cloud/common uses a lot of dependencies #1514

Description

@MarkHerhold

TL;DR: Please focus on gradually reducing the number of dependencies going forward.

I was looking at using the @google-cloud/pubsub module and wanted to dive deeper into how auth worked and ended up in @google-cloud/common. It turns out that @google-cloud/common alone downloads about 39 MiB (~5MB) of files. Awesome! 👍

I don't have any solid recommendations for reducing the number of dependencies but just wanted to bring this up as something to think about going forward.

For instance, did you know that @google-cloud/common indirectly depends on three separate versions of request?

$ find ./node_modules -name request
./node_modules/google-auth-library/node_modules/request
./node_modules/grpc/node_modules/node-pre-gyp/node_modules/request
./node_modules/request

$ cat ./node_modules/google-auth-library/node_modules/request/package.json | jq .version
"2.60.0"

$ cat ./node_modules/grpc/node_modules/node-pre-gyp/node_modules/request/package.json | jq .version
"2.72.0"

$ cat ./node_modules/request/package.json | jq .version
"2.74.0"

Take a look at this awesome dependency visualization of @google-cloud/common if you have a minute.

http://npm.anvaka.com/#/view/2d/%2540google-cloud%252Fcommon

Activity

  1. stephenplusplus commented on Aug 21, 2016

    @stephenplusplus
    Contributor

    This is not a problem unique to our library. It's well known that npm's hyper-modular approach brings the cost of many dependencies. All we can do is watch how many dependencies we take on, and of course we do. npm version 3 is helping by enabling de-duplicating packages by default. We can't control what other libraries take on as dependencies, so that's when we end up with multiple versions of the same dependency.

    If you have concrete suggestions of alternative packages that offer the same benefits as the ones we use, please let us know-- or better yet, PR! As an ecosystem at whole, that's the best way to help each other. I've sent many PRs in the past to heavy modules to introduce the files array from package.json to eliminate excess downloads.

    I'm going to close, but to be clear, we do think about this and we do hear you.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions