npm inc are complicit in this
https://github.com/eslint/eslint-scope/issues/39#issuecomment-404533026 …
-
-
If this functioned like a real open source project and not a VC capitalist enterprise startup then they’d be working on the features that open source devs actually want.
Show this thread -
I started
@yarnpkg precisely because I, and everyone I talked to, thought that npm didn’t give a fuck about them. npm loves you? More like npm loves the VC money.Show this thread -
Market forces can’t unseat someone in a position of monopoly either. Think about it. A VC backed company have their software in one of the largest programming platforms. Nobody else can “compete”.
Show this thread -
That’s why I find it ridiculous when npm inc play the underdog. You’re the monopoly that’s disrupting innovation. With the CLI you can only do so much (a la Yarn), controlling server infrastructure is critical.
Show this thread -
Most people don’t know that most of npm’s software is closed source. You want to build a new backend or mirror the registry? Haha! Have fun buddy! You gotta pay for an enterprise license to do anything like that.
Show this thread -
Reminder: npm inc regularly gloat that Yarn is irrelevant and shouldn't exist. Ironic to see subtweets complaining about me not wanting npm inc to exist.
Show this thread
End of conversation
New conversation -
-
-
Dumb q: how would code signing prevent this? npm would store public keys, so you’d need a valid token and a private key to publish a package? Is then assumption that it’s harder to steal both a token and a private key?
-
Yep. It doesn’t completely mitigate package hijacking but it increases the barrier.
- 1 more reply
New conversation -
-
-
Minimally they could do like
@chocolateynuget and default to asking you to approve the script it runs on install. Why is that any more than like an hour of work?Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
he/him 
response is not acceptable.