npm inc are complicit in this
https://github.com/eslint/eslint-scope/issues/39#issuecomment-404533026 …
-
Show this thread
-
npm inc when there was literally a CVE by
@samccone about this. only thing that came from it is 2fac. code signing WOULD have prevented this. Over 2 years to do something so the
response is not acceptable.https://blog.npmjs.org/post/141702881055/package-install-scripts-vulnerability …3 replies 5 retweets 41 likesShow this thread -
If this functioned like a real open source project and not a VC capitalist enterprise startup then they’d be working on the features that open source devs actually want.
2 replies 1 retweet 26 likesShow this thread -
I started
@yarnpkg precisely because I, and everyone I talked to, thought that npm didn’t give a fuck about them. npm loves you? More like npm loves the VC money.3 replies 1 retweet 49 likesShow this thread -
Market forces can’t unseat someone in a position of monopoly either. Think about it. A VC backed company have their software in one of the largest programming platforms. Nobody else can “compete”.
2 replies 2 retweets 16 likesShow this thread -
That’s why I find it ridiculous when npm inc play the underdog. You’re the monopoly that’s disrupting innovation. With the CLI you can only do so much (a la Yarn), controlling server infrastructure is critical.
5 replies 2 retweets 25 likesShow this thread -
Replying to @sebmck
Fair, but Facebook is hardly an underdog either. I like, use, and contributed to Yarn, but I don't think either yarn or npm can claim to be the underdog.
2 replies 0 retweets 7 likes
Facebook has a lot of influence in the global community and marketplace. As a software engineer at Facebook though, being employed by Facebook does give me the liberty to spend company time working on open source but I don’t think there’s much more.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
he/him 