HomeSecurityOne-line npm package creates issues in JavaScript ecosystem

One-line npm package creates issues in JavaScript ecosystem

JavaScript One-line npm

An update to a small JavaScript library (a one-line npm package) caused major chaos in the JavaScript ecosystemon Saturday, and millions of projects are believed to have been affected.

The chaos was caused by a "one-liner" JavaScript library, and it's the second time a tiny JavaScript project has caused such widespread problems.

Is-promise one-liner

The library at the heart of the problems is called is-promise. The library consists of two lines of raw source code, and developers can use it in their projects via a one-liner call.

The is-promise library is one of the most popular JavaScript npm packages. According to GitHub, it is part of more than 3.4 million projects and is used as a dependency by 766 other JavaScript libraries.

Over the weekend, the one-line npm package is-promise was updated to work as an ES module (the standard system used by the JavaScript language).

However, the is-promise v.2.2.0 version did not comply with the proper ES module standards. As soon as the update was released , projects using is-promise started having problems due to the incorrect ES module.

The impact of the bug was felt immediately and affected many small and large JavaScript projects, such as Facebook 's Create React App , Google 's Angular.js framework , Google 's Firebase tools , Amazon AWS Serverless CLI, Nuxt.js, AVA, and others.

The bug did not cause problems in existing projects, but it prevented developers from pushing new versions of their projects.

The same thing happened again in 2016

This is the second time that a small JavaScript library has caused problems for the entire JavaScript system. Something similar happened in March 2016, when the creator of the left-pad JavaScript library suddenly decided to stop releasing the library, causing issues for many projects.

As happened in 2016, the incident with the is-promise npm package raised questions and started discussions about the need for one-liner libraries to be available in the ecosystem.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS