Contents

Engineering Craft › Developer Tooling

Dependency

External code your project relies on.

Also known as: dependencies, library dependency, third-party package

A dependency is external code that your project relies on: a library, a framework, a package. You use it instead of writing that functionality yourself.

"dependencies": { "express": "^4.18.0", "zod": "^3.22.0" },
"devDependencies": { "vitest": "^1.6.0" }
requests==2.32.0        # requirements.txt (Python)

Kinds

  • Runtime dependencies: needed when the app runs.
  • Development dependencies: needed to build, test and lint (a test runner, a formatter).
  • Transitive dependencies: the dependencies of your dependencies, installed automatically (transitive dependencies).
  • Services: databases, APIs and queues your system depends on, which are dependencies in a wider sense.

Why they matter

Dependencies save huge amounts of work, and they also bring cost:

  • Bugs and breaking changes from upgrades.
  • Security risk: a vulnerable or malicious package affects you (supply chain security, dependency scanning).
  • Maintenance risk: an abandoned library becomes your problem.
  • Size and slowness: extra weight in bundles and install times.
  • Conflicts between versions (dependency hell).

Habits

  • Add them deliberately. Is it maintained, widely used, and worth it for what you need? Don’t pull in a package for one small function.
  • Pin versions with a lockfile and update on purpose.
  • Keep them current in small steps, with tests.
  • Remove unused ones.
  • Check licenses (open source licenses).
  • Isolate them behind your own small interfaces where changing libraries might be needed.

In design talk, “dependency” also means anything a class needs to do its job (dependency injection).