|
|
|
|
|
by ebfe1
279 days ago
|
|
Is it just me who think this could have been prevented if npm admins put in some sort of cool off period to only allow new versions or packages to be downloaded after being published by "x" amount of hours? This way the npm maintainer would get notifications on their email and react immediately? And if it is urgent fix, perhaps there can be a process to allow npm admin to approve and bypass publication cool off period. Disclaimer: I don't know enough of npm/nodejs community so I might be completely off the mark here |
|