Hacker News new | ask | show | jobs
by rndhouse 1690 days ago
Hello megumax!

I'm working on a solution along the lines that you've suggested:

https://github.com/vouch-dev/vouch

Vouch lets users create and share reviews for NPM packages. Project dependencies can then be checked against those reviews.

Vouch uses extensions to interface with package ecosystems. Extensions currently exist for NPM, PyPi, and Ansible Galaxy.

I'm currently working on a website to index known reviews and publish official reviews.

Drop by the Matrix channel if you have any feedback or thoughts to share: #vouch:matrix.org