NPM package rejected by corporate firewall
Personne n'a encore pris cette issue.
Évaluation
- Difficulté
- 4/5
- Temps estimé
- 3-5 jours
- Accessibilité débutants
- 25/100
- Type d'issue
- Refactorisation
- Clarté
- Plutôt claire
- Activité
- À l'abandon
- Stack technique
- javascript, node.js
- Domaine
- cli
Piste de recherche
Commencez par inspecter package.json et la dépendance citée sur github.com/telerik/node-bplist-parser/tarball/master. Vérifiez les autres dépendances directes GitHub mentionnées dans le rapport, puis déterminez si le fork concerné est disponible via npm ; le travail est terminé lorsque les dépendances concernées ne nécessitent plus d’accès à GitHub pour l’installation.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Description
Did you verify this is a real problem by searching the NativeScript Forum and the other open issues in this repo?
Yes. It has been reported in:
https://discourse.nativescript.org/t/installing-nativescript-from-behind-a-corporate-proxy/696
Tell us about the problem
Please, ensure your title is less than 63 characters long and starts with a capital
letter.
The organization I work at requires NPM packages to require dependencies only from NPM. NPM, too, advises against git dependencies. See https://blog.npmjs.org/post/145724408060/dealing-with-problematic-dependencies-in-a: "Generally, we discourage using Git dependencies in package.json, and it’s typically only used temporarily while a maintainer waits for an upstream fix to be applied and published."
When I tried to get NativeScript added to the internal repo for use by developers across the enterprise, my request was rejected because of Github dependencies.
Specifically, the approval team said this module has a dependency on https://github.com/telerik/node-bplist-parser/tarball/master, but the local repo cannot proxy to github.
They advised me to ask you if you could update the above-cited dependency to use a package in the npm registry. They warned that this might be complicated because of the fact that the dependency is a git fork of an npm package. They said you would need to publish your fork on npm and then update this module to use that npm package. This, they argued, would make the module more "corporate firewall friendly", which I assume would promote NativeScript's market share. They said proxying to github in the future is a possibility, but it brings added risk with it. And, per NPM as cited above, github dependencies don't seem to be a best practice anyway.
What I don't understand is why my company's team cited only one github dependency, when package.json seems to show several direct ones. If that needs clarification, I can ask them for it.
Which platform(s) does your issue occur on?
Both
Please provide the following version numbers that your issue occurs with:
- CLI: (run
tns --versionto fetch it)
4.2.2
Please tell us how to recreate the issue in as much detail as possible.
That does not seem practical.
- Langage dominant
- JavaScript
- Étoiles
- 1.1k
- Forks
- 204
- Merge moyen
- 1 j 9 h
- PR mergées (30 j)
- 8
Guide de contribution
Ouvrir le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de NativeScript/nativescript-cli
-
in-progress
NativeScript/nativescript-cli#6140 · 2 commentaires · 1 personne assignée ·
-
NativeScript/nativescript-cli#6090 · 1 personne assignée ·
-
in progress
NativeScript/nativescript-cli#6015 · 1 réaction · 1 personne assignée ·
-
question
Difficulté 4/5 3-5 jours Accessibilité débutants 48/100
NativeScript/nativescript-cli#5992 · 5 commentaires ·
-
feature-pending-triage
Difficulté 4/5 3-5 jours Accessibilité débutants 35/100
NativeScript/nativescript-cli#5975 ·
Toutes les issues de NativeScript/nativescript-cli
Issues similaires
-
Edit: CW+ Ouvertechannels:edit check:passed
Difficulté 2/5 1-3 heures Accessibilité débutants 68/100
-
스택 PR 머지 시 하위 PR base 재지정 단계 부재 Ouverte
Difficulté 2/5 1-3 heures Accessibilité débutants 78/100
idean3885/claude-ops-agent#521 ·
-
[Nytt ikon]: menu-search Ouverteforespørsel 🥰 ikoner 🖼 nytt ✨
Difficulté 2/5 1-3 heures Accessibilité débutants 68/100
-
bug
Difficulté 2/5 1-3 heures Accessibilité débutants 76/100
avniproject/avni-client#2135 ·
-
automated broken-link
Difficulté 1/5 Moins d'une heure Accessibilité débutants 85/100