zlacker

[parent] [thread] 9 comments
1. angry_+(OP)[view] [source] 2025-07-28 16:10:48
No deps is great, but what I'm looking for is no bugs, authentication and encryption. I want features turned off by default, configs tight as a drum.
replies(5): >>neuroe+96 >>bakugo+O8 >>corndo+6p >>Fuzzwa+oP >>einste+t33
2. neuroe+96[view] [source] 2025-07-28 16:45:17
>>angry_+(OP)
Obviously, that is not this
3. bakugo+O8[view] [source] 2025-07-28 16:59:37
>>angry_+(OP)
If you're looking for security and stability, I would personally avoid this.

I took a glance at the code and it's... not great. It's absolutely full of short, meaningless 1-2 letter variable and function names that make it very hard to read and understand if you're not the original author. Wouldn't be surprised if it's full of security holes that will never be found.

replies(3): >>snerbl+lA >>tripdo+SN >>jshpre+7S
4. corndo+6p[view] [source] 2025-07-28 18:31:08
>>angry_+(OP)
This is just good software
◧◩
5. snerbl+lA[view] [source] [discussion] 2025-07-28 19:24:51
>>bakugo+O8
According to the author it was mostly written on the train with his phone, that could explain the terse naming.
replies(1): >>physic+NR
◧◩
6. tripdo+SN[view] [source] [discussion] 2025-07-28 20:39:51
>>bakugo+O8
FWIW, it just had an XSS vulnerability fixed yesterday: https://github.com/9001/copyparty/security/advisories/GHSA-9...
7. Fuzzwa+oP[view] [source] 2025-07-28 20:45:59
>>angry_+(OP)
This section of the readme really sets the expectation clearly:

> inverse linux philosophy -- do all the things, and do an okay job > - quick drop-in service to get a lot of features in a pinch > - some of the alternatives might be a better fit for you

This includes a link to this doco in the repo which is an incredible source of info: https://github.com/9001/copyparty/blob/hovudstraum/docs/vers...

◧◩◪
8. physic+NR[view] [source] [discussion] 2025-07-28 20:58:17
>>snerbl+lA
This is a developer flex if I ever heard one
◧◩
9. jshpre+7S[view] [source] [discussion] 2025-07-28 20:59:55
>>bakugo+O8
From the README FAQ section:

> i want to learn python and/or programming and am considering looking at the copyparty source code in that occasion

> do not

10. einste+t33[view] [source] 2025-07-29 14:36:39
>>angry_+(OP)
> No deps is great, but what I'm looking for is no bugs

I don’t think I’ve ever used a piece of software in my life that had no bugs. At least with no deps (vs say a nodejs project with 500 of them) then the bugs will only be in one place, the main software so ideally they can be fixed quickly.

[go to top]