Hacker News new | ask | show | jobs
by nosefurhairdo 891 days ago
Perhaps NPM should apologize for shifting blame and failing to address the root cause.

The wildcard "any version of dependency" preventing unpublish is clearly flawed. The "everything" package folks had no malicious intentions, and nobody would benefit from a long-winded, ashamed apology. If not for NPM's flawed unpublish policy the everything team would've unpublished to resolve the issue.

1 comments

I agree to a large extent but I am not sure even rereading my comment that I can take that that’s what I am advocating for.

I just think it would have been good to give the “I was hoping to investigate X, I did not expect Y, I can see now that it was irresponsible to do X.”

I don’t think that’s particularly long winded.

I don't think he was trying to investigate anything. He was just trolling, but he didn't intend to troll _that hard_.