1 of 35

Package & Dependency Management

Fall 2026

1

2 of 35

Outline

  1. Warmup problem
  2. More on Docker
  3. Discussion of Readings
  4. Exploration of different package managers
  5. More time for Lab 4

2

3 of 35

Outline

  • Warmup problem
  • More on Docker
  • Discussion of Readings
  • Exploration of different package managers
  • More time for Lab 4

3

4 of 35

Warmup Problem: Anagram Detector

An anagram is a word or phrase formed by rearranging the letters of another word or phrase, using all the original letters exactly once.

  • Examples:
    • listen → silent
    • evil → vile
    • state → taste
  • Usually, spaces and capitalization are ignored when checking phrases.
  • Letters can repeat in an anagram, but the repeated letters have to appear the same number of times in both.

5 of 35

Warmup Problem: Anagram Detector

Make a folder in your csci338 folder called lecture06. Create a file called anagrams.py and implement this function in Python:�

def are_anagrams(a: str, b: str) -> bool:

pass

​

​

assert are_anagrams("listen", "silent") is True

assert are_anagrams("hello", "world") is False

​

​

6 of 35

Outline

  1. Warmup Problem
  2. More on Docker
  3. Discussion of Readings
  4. Exploration of different package managers
  5. More time for Lab 4

6

7 of 35

What did you think of Docker?

8 of 35

Images, Containers, and Volumes

  • What is an Image?
  • What is a Container?
  • What is a Volume?
  • What is a Bind Mount?
  • What is the purpose of a Dockerfile?
  • What is the purpose of a docker-compose.yml file?

9 of 35

Docker: Cool Stuff

With Docker, you can install containerized versions of new libraries, languages, etc. without having to worry about software incompatibilities with your existing OS / software libraries.

  • With Docker, just run whichever version of your language in a container…and then delete the container when you’re done with it!

10 of 35

Docker Experiments

​

Please try the following (make sure that Docker is running):

docker run -it python:2.7

docker run -it python:latest

docker run -it node:latest

​

What happened?

  • How did Docker know how to run these containers?
  • What do the -i and -t flags do?
    • -i interactive
    • -t interact with the terminal shell

10

11 of 35

Docker Experiments

​

Try running some local files with various versions of Python and Node:

  • Inside of lecture06, create two files: hello.py and hello.js

hello.py

def main():

print("hello world")

​

if __name__ == "__main__":

main()

�hello.js

console.log("hello world!")

11

12 of 35

Docker Experiments

​

docker run python:latest python hello.py

docker run node:latest node hello.js

​

What did that do? Why didn’t it work?

​

12

13 of 35

Docker Experiments

​

docker run --rm -v "$PWD":/app -w /app python:latest python hello.py

​

docker run --rm -v "$PWD":/app -w /app node:latest node hello.js

​

​

-v "$PWD":/app → make your current host folder visible as /app in the container

-w /app → run from /app

python hello.py → execute the file there

​

​

13

14 of 35

Docker Experiments

​

Now delete the containers and images that were just created.

​

​

14

15 of 35

What if you wanted to try out Rust?

  • Download, build, and run the Rust container: �docker run -it rust:latest bash
  • Install vim:�apt update && apt install vim
  • Create a hello.rs file on the Docker container using vim: (https://doc.rust-lang.org/rust-by-example/hello.html)
  • Compile it: rustc hello.rs
  • Run it: ./hello

16 of 35

Outline

  1. Warmup Problem
  2. More on Docker
  3. Discussion of Readings
  4. Exploration of different package managers
  5. More time for Lab 4

16

17 of 35

What do we mean by Dependency Management?

  • What is a dependency?
    • Something that depends on something else
    • Software the requires external libraries
    • ​
  • Why are they so hard to manage?
    • People.
    • A recursive thing.
    • Dependencies depend on dependencies

17

18 of 35

What happened in the LeftPad Debacle?

Scene 1: Tiny package, huge dependency chain

  • left-pad was only a few lines of code
  • But many major JavaScript tools depended on it indirectly.

Scene 2: A naming dispute

  • Developer Azer Koçulu had an npm package named kik.
  • The company Kik wanted that package name.
  • npm decided the name should go to Kik under its dispute policy.

Scene 3: The developer removes his packages

  • Koçulu unpublished kik and 272 other packages, including left-pad.
  • Suddenly thousands of builds failed because their dependency chains could no longer retrieve left-pad.

19 of 35

What happened in the LeftPad Debacle?

Scene 4: npm restores left-pad

  • npm took the unusual step of restoring the original left-pad@0.0.3. The disruption lasted about 2.5 hours.

Scene 5: npm changes the rules

  • npm concluded that unrestricted unpublishing was too dangerous
  • Introduced stricter rules limiting when packages with dependents could be removed.

20 of 35

Big idea

A tiny piece of software can become critical infrastructure when enough other software depends on it.

21 of 35

What happened in the Everything Debacle?

  • “everything” package – An npm user published a package that depended on every public npm package, creating millions of transitive dependencies.
    • Intended as a prank
  • Unintended denial-of-service effect – Installing it could exhaust storage and other system resources, causing installs to fail or systems to crash.
  • Unintended ecosystem consequence – After recognizing the disruption, the creator could not simply unpublish it because of npm’s stricter removal policies introduced after the left-pad incident.

22 of 35

What are the trade-offs associated with relying on dependencies?

​

What are dependencies good?

  • Save time and maintainance

​

What are the downsides?:

  • Could be more efficiently written

22

23 of 35

What should you consider before adding a new dependency to your software project?

​

  • Your thoughts here…

23

24 of 35

Stuff that can go wrong…

​

  • If “DepA” was introduced, and now lots of people at your organization rely on DepA, who should maintain it?
  • What if one of the dependencies that DepA relies on – DepB – has a security vulnerability. DepB now requires that you upgrade to a newer version, but DepA relies on the previous version of the dependency. What do you do?

24

25 of 35

Some dependencies we will be using…

This week: Python & JavaScript dependencies – how do we manage those!? Examples:

  1. Database connection helpers
  2. Packages for simplifying HTTP requests
  3. Web server packages
  4. REST API packages
  5. Authentication
  6. Widgets for building UIs

25

26 of 35

Layers of Dependencies

​

Systems dependency managers manage programs for a single host machine.

What are some examples of systems dependency managers?

  • OS: brew. Linux: apt, dnf, yum. Window: winget, chocolatey
  • Python: pip, poetry
  • Node: npm, yarn, npmpm

26

27 of 35

Outline

  1. Warmup Problem
  2. More on Docker
  3. Discussion of Readings
  4. Exploration of different package managers
  5. More time for Lab 4

27

28 of 35

Why might we need more fine-grained dependency management tools?

​

As a programmer who writes software, a global, system-level dependency management tool might not be enough! Why?

  • Multiple software projects may rely on multiple versions of the same language or framework
    • Different versions lead to different behaviors
  • Different language features / environments move at different time scales, so system-level packages can be old
    • Your OS package manager could install an older version of the tool you need

28

29 of 35

JavaScript Dependency Management

Make sure Node.js is installed…

  • ex: npm is for front-end development (also yarn)

$ npm init

$ npm install react react-dom

$ npm install prettier --save-dev

​

  • npm manages package.json and package-lock.json
  • Dependencies are stored in the node_modules directory at the root of the project
  • Exclude node_modules from version control. Why?

30 of 35

Python Dependency Management

  • pip is a package manager used to install system-level python packages.
  • However (important): you can create “virtual environments” (venv) – additional python installations that don’t conflict with your systems-level Python installation(s).
  • To manage these virtual environments, wrappers around pip and venv are now used

31 of 35

Python Dependency Management: Poetry

  • In this class, we will be using a tool called Poetry to manage python virtual environments
  • Poetry manages pyproject.toml and poetry.lock files

$ pip install poetry

$ poetry init

$ poetry search request

$ poetry add request

$ poetry install

$ poetry run [whatever]

32 of 35

Common Features of a Good Package Manager

Poetry and NPM provide:

  • A Nice CLI (command-line interface)
  • Text-file dependency tracking (for version control) – usually declarative
  • Reproducibility

​

33 of 35

Lab 5: Practice Using Package Managers

​

On Thursday, you will be doing a lab to explore some dependencies using three different package managers:

  1. Apt / brew
  2. Poetry
  3. NPM

​

See you Thursday!

33

34 of 35

Outline

  1. Warmup Problem
  2. More on Docker
  3. Discussion of Readings
  4. Exploration of different package managers
  5. More time for Lab 4

34

35 of 35

Keep working on Lab 4