Skip to content

Questioning the need for user package dependency #406

@mcecode

Description

@mcecode

Hi, feel free to close this if I'm mistaken and there's actually no problem, but I just want to ask why pdf2json suddenly needed to depend on the user package?

"user": "^0.0.0"

It was added in b03348e right before the release of Stable build: V3.2.1. The release notes actually claim:

keeping zero dependency

which is false.

The user package hasn't been updated in 12 years and doesn't really seem to do anything either:

Image

It's kind of suspicious that a package like this is suddenly depended on. Actually, I can't believe that a package like this has any dependents at all, let alone 2807. Just can't help but be a bit paranoid with all the npm exploits being reported these days.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions