Hacker News new | ask | show | jobs
by dontscale 3735 days ago
For those of us who are pissed that this is going down but need the status to get on with our lives:

nj48 is a known friendly who has identified himself to us. We're going to clarify later today.

https://twitter.com/seldo/status/712673227630313472

2 comments

I bet the orig dev was considered a known friendly until he decided to unpublish.

Relying on the notion of a "known friendly" to protect packages and namespace does not strike me as a sound practice.

As others may have mentioned, publishing packages really should be fire and forget. If something bad goes out, a replacement should be sent out. And for the life of me, I don't understand why they did not go with the <author/package> scheme.

Yes, as far as I've heard, this was done defensively to prevent malicious actors from claiming these packages.

Also, relevant conversation here in yesterday's thread: https://news.ycombinator.com/item?id=11340510