I think there should be some serious changes about this. Github already knows which software packages a company uses. They could facilitate this. For example if the OSS maintainer asks for it, any company more than say three members should pay a monthly fee per package. Even 1 USD per package per month would make a huge difference for OSS. So if your javascript package.json has 20 dependencies, and you are actively developing, every month you should expect to pay 20USDfor that package.json.I know the math above can be challenged from multiple aspects. But we need to start from somewhere.
balder1991|2 years ago
cxr|2 years ago
The proliferation of tiny NPM packages is bad enough already. It will only be made worse by the cobra effect.
DonHopkins|2 years ago