Hacker News new | ask | show | jobs
by WorldMaker 2766 days ago
Another easy suggestion is that NPM could have forced a semver major change on the new maintainer. It would have been an easy signal for people to check what changed, and fewer developers would have accidentally installed the infected version because it was only a "minor" change.