Comment on When "Everything" Becomes Too Much: The npm Package Chaos of 2024 - Socket
UnculturedSwine@lemmy.world 9 months agoI feel like you could also give the maintainers the power to “re-publish” using a different verified maintainer so that if such a thing does happen, it can be reversed without input from the maintainer that originally pulled it. I don’t know enough about the system to really know if this is a good idea tho.
locuester@lemmy.zip 9 months ago
Yeah then you’ve got security problems. If a maintainer pulls a package, you wouldn’t want some rando able to push a new one in its place.