@shinspiegelJeferson 'Shin' That's a fair concern in general, but it applies to any dependency, not just CLI parsers. Optique's core package has zero runtime dependencies, which keeps the attack surface minimal. If supply chain security is a priority, you could also vendor the code or pin to specific versions. That said, manually parsing process.argv for anything beyond trivial cases tends to introduce its own bugs.
@hongminhee洪 民憙 (Hong Minhee) Good point. But if I may ask, how often do your CLI tools and utilities require more than 2~5 arguments? In my professional (and personal) work, I think I encountered a couple of cases, which we broke down into two/three different utilities and used the stdin/stdout with good piping.
If you have a fediverse account, you can quote this note from your own instance. Search https://mastodon.social/users/shinspiegel/statuses/115847489807460814 on your instance and quote it. (Note that quoting is not supported in Mastodon.)