Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A large part of npm's staggering success is the very low friction to publish packages. I worry that any mitigation that slows down the publishing side of things would kill innovation in the ecosystem.


I imagined an optional delay for npm install/update. That way it would only slow down users who wanted more time.


Got it. Yea I agree that's useful and easy mitigation, and I'm sure enterprise users would certainly pay for other safety labeling/filtering/signing of packages.


It makes so much sense, surprised me that it doesn't exist.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: