▲ | parliament32 4 days ago | ||||||||||||||||||||||
The NPM team has repeatedly commented that it's "too hard", effectively, and would discourage new developers from publishing packages. See: https://github.com/npm/npm/pull/4016#issuecomment-76316744 https://news.ycombinator.com/item?id=38645969 https://github.com/npm/cli/commit/5a3b345d6d5d175ea9ec967364... | |||||||||||||||||||||||
▲ | a022311 4 days ago | parent | next [-] | ||||||||||||||||||||||
I don't think I'd trust a package from a new developer like that, so this helps filter out people that don't know how to properly maintain a package. If they really want to make onboarding easier, saying "after e.g. 1000 monthly downloads, you'll need to sign your artifacts" is also a viable solution in my opinion. | |||||||||||||||||||||||
▲ | metafunctor 4 days ago | parent | prev | next [-] | ||||||||||||||||||||||
The npm team is, frankly, a bunch of idiots for saying that. It has been obvious for TEN YEARS that the bar for publishing npm packages is far too low. That’s what made npm what it is, but it’s no longer needed. They should put on their big boy pants. | |||||||||||||||||||||||
▲ | jiggawatts 4 days ago | parent | prev [-] | ||||||||||||||||||||||
> discourage new developers from publishing packages Good. | |||||||||||||||||||||||
|