If I'm not mistaken, npm5 makes yarn obselete: npm5 has fast install, lock file (even better than yarn's), plus nothing extra to install.
-
-
Mitm? That's an irresponsible way to describe the simple and common reverse proxy. You should read this: https://en.m.wikipedia.org/wiki/Reverse_proxy …
1 reply 0 retweets 2 likes -
There's no legitimate technical reason for Yarn to man-in-the-middle traffic to the npm registry. If it's not spyware, it's at least icky
1 reply 6 retweets 11 likes -
Replying to @feross @HunterLoftis and
I believe they used to just have a CNAME that pointed to the npm registry but now it's proxying with an A record. Why?
1 reply 0 retweets 4 likes -
Replying to @feross @HunterLoftis and
Even if just for analytics, it's not worth the risk. Now if either npm *or* yarn is hacked, you are compromised.
1 reply 0 retweets 3 likes -
Replying to @feross @HunterLoftis and
I'm sure
@sebmck has good intentions, but does his reverse proxy have all patches applied? At least npm pays for security audits3 replies 0 retweets 4 likes -
Replying to @feross @HunterLoftis and
I think there's still some confusion around how our proxy actually works. We use Cloudflare which is literally reverse proxy as a service.
2 replies 0 retweets 3 likes -
We host no servers. All we configure is the Cloudflare UI to specify that requests to http://registry.yarnpkg.com go to http://registry.npmjs.com pic.twitter.com/lDZgSItyja
1 reply 0 retweets 3 likes -
Cloudflare are the ones who handle security updates. Being concerned about Cloudflare's security makes sense but odds are you're already...
1 reply 0 retweets 1 like -
trusting them. Some of their customers are DigitalOcean, Hacker News, Medium etc. Sites you probably already use.
1 reply 0 retweets 2 likes
Yes there's implicit trust that we wouldn't go rogue and change the registry for nefarious purposes.
-
-
But that trust already exists because we could just as easily do it in the client source code.
3 replies 0 retweets 2 likes -
Also using Yarn you aren't forced to use our proxy. You could just as easily use the main one, in fact we respect all of your .npmrc options
0 replies 0 retweets 2 likes
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
he/him 