Conversation

Replying to and
imho npm has a *trust* issue, and it's not fixed by reducing its handy features ... example:
Quote Tweet
Replying to @bitandbang and @npmjs
What saddens me is that ther e is zero signal in npm about 2FA being used for a module. A badge, a security check, nothing. npm info module? Zero! Make it recognizable and see people running for it to show off how much they care 🤷‍♂️
1
1
Show replies
Replying to and
FWIW I've been chatting with folks on the team about how we can get rid of install / postinstall scripts the last two weeks. The biggest thing is figure out how to support the native module story better in a way that doesn't require dynamism at install time.
1
5
Replying to and
NAPI is great for making binaries that support multiple versions of Node.js, but they are still platform specific. WASM + WASI offer a potential platform agnostic future, but that isn't here yet. So we are still stuck with the challenge of lazy loading binary extensions
1
1
Show replies