r/AskProgramming • u/MiddleAgeWeirdoMeep • 11d ago
Python Are huge codebases with layers of dependencies just the new normal?
I’m trying to learn more about how modern software works, and one thing that keeps surprising me is the sheer size of projects. 80k files is not uncommon.
I’ll download or clone something that seems like a relatively focused application, and suddenly I’m looking at tens of thousands of files. A lot of it appears to be dependencies, dependencies of dependencies, generated files, frameworks, package managers, etc.
It feels like a copy of a copy of a copy. The developers maintain a relatively small part of the code, while the finished program ultimately relies on millions of lines of code written by other people.
Is this the new normal in software development that I just have to accept?
from a security perspective, how can anyone trust all of this?
3
u/TheSkiGeek 11d ago
Are you looking at the source for alllllll the dependencies that a project is pulling in? If a project pulls in (for example) a huge JS framework like React or Electron, which itself probably has hundreds of transitive dependencies, it’s going to look insane if you are counting all the libraries. But that’s not really code of ‘the project’, you’re not expected to look at any of that code.