Conversation

Hey internet, Here is my statement on the event-stream issue: gist.github.com/dominictarr/9f Thanks to everyone who sent me friendly emoji ;) I'm okay. But this is really a much bigger issue (the viability of open source). I'm glad that this incidence is raising awareness!
42
1,403
Replying to
It's incredible to me the amount of baseless praise you're getting for putting so many people at risk of getting pwnd. Of course, much of it is to be expected for Twitter. You messed up, and you should realize you messed up and apologize. Simple as. Nothing praise worthy here.
3
1
Replying to
It does not need to be maintained. You could mark it as unmaintained and leave it as-is. If someone wanted to maintain it they can fork it and put it up on NPM themselves. No need to give away NPM publish rights on your package. How do you not understand this?
2
Replying to and
They did maintenance and implemented a previously requested feature with an appropriate library, where they hid the backdoor. They could have contributed first to build trust if needed. Few projects do much vetting of contributors before entrusting them with commit access, etc.
1
Replying to and
It does appear a significant portion of the npm community applies a much lower bar than I'm used to for giving out commit access or turning over maintainership. However, the usual criteria is just that people contributed useful changes for a while and appear decent and competent.
1
Show replies