Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What’s the fix here?

Maintainers should be able to do whatever they want either their code

But if they vandalize their modules that should be a lifetime ban from the registry

It’s pretty obvious that node needs a better method for dealing with this by now



Companies/people should do due diligence and not accept libraries just because they are free somewhere on the internet and stop "staring".

This would make libraries less popular and would make "stars"/"downloads" less of a misguided status symbol that is only making things worse, because the more "stars"/"downloads" people have the better they feel. Then comes hangover when reality hits and such person is left with silly numbers that are not going to buy anything but also not helping to land a job.

That would make people who should not be in a maintainer position not to be there as it would stop being so attractive.

In the end there would be libraries/frameworks created by corporations that can afford that or by real enthusiasts that understand what they sign up for.

Did Linus Torvalds made Linux to be famous - not - he did it because he liked to have it. He made it into career and got famous, but he is an exception not the rule. There is too much people who are in it for the wrong reasons that is my conclusion.


No. Maintainers should be able to publish whatever they want. Users should save whatever they want to consume locally for whatever specification of local (disk, mirror, whatever) works for them. Malicious actions will be rejected and punished by the marketplace. If GitHub et al want to be a value of local, i.e. controlled by the (community of) users then they can play that role, but no one should expect them to




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: