Hacker News new | ask | show | jobs
by smoldesu 1478 days ago
Sounds like a pretty bad policy if that inhibits your ability to respond to critical security flaws in your package.
1 comments

The npm ecosystem has been shown over and over again to be a dysfunctional tire fire.

I feel like at this point continuing to publish on npm is kind of a "that's what you get" situation.