Is it just me who think this could have been prevented if npm admins put in some sort of cool off period to only allow new versions or packages to be downloaded after being published by "x" amount of hours? This way the npm maintainer would get notifications on their email and react immediately? And if it is urgent fix, perhaps there can be a process to allow npm admin to approve and bypass publication cool off period.Disclaimer: I don't know enough of npm/nodejs community so I might be completely off the mark here
herpdyderp|5 months ago
kaelwd|5 months ago
https://github.com/pnpm/pnpm/issues/9921
balder1991|5 months ago
kaelwd|5 months ago
mdaniel|5 months ago
But, this coming from GitHub, who believe that sliding "v1" tags on random action repos is how one ends up with https://news.ycombinator.com/item?id=43367987
robjan|5 months ago
hiccuphippo|5 months ago