npm inc when there was literally a CVE by @samccone about this. only thing that came from it is 2fac. code signing WOULD have prevented this. Over 2 years to do something so the
response is not acceptable.https://blog.npmjs.org/post/141702881055/package-install-scripts-vulnerability …
-
-
Show this thread
-
If this functioned like a real open source project and not a VC capitalist enterprise startup then they’d be working on the features that open source devs actually want.
Show this thread -
I started
@yarnpkg precisely because I, and everyone I talked to, thought that npm didn’t give a fuck about them. npm loves you? More like npm loves the VC money.Show this thread -
Market forces can’t unseat someone in a position of monopoly either. Think about it. A VC backed company have their software in one of the largest programming platforms. Nobody else can “compete”.
Show this thread -
That’s why I find it ridiculous when npm inc play the underdog. You’re the monopoly that’s disrupting innovation. With the CLI you can only do so much (a la Yarn), controlling server infrastructure is critical.
Show this thread -
Most people don’t know that most of npm’s software is closed source. You want to build a new backend or mirror the registry? Haha! Have fun buddy! You gotta pay for an enterprise license to do anything like that.
Show this thread -
Reminder: npm inc regularly gloat that Yarn is irrelevant and shouldn't exist. Ironic to see subtweets complaining about me not wanting npm inc to exist.
Show this thread
End of conversation
New conversation -
-
-
He should be pulling source code from the origin (any git repo) instead of private repositories
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
Show additional replies, including those that may contain offensive content
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
he/him 