logoalt Hacker News

brunoborgestoday at 2:14 AM1 replyview on HN

It is 100% up to the package manager's steward to control how ownership of packages and namespaces are granted.

Maven Central exists for decades the amount of incidents of people stealing namespaces is minimal.

One can't simply publish a package under the groupId "com.ycombinator" without having some way to verify that they own the domain ycombinator.com. Then, once a package is published, it is 100% immutable, even if it has malicious code in it. Certainly, that library is flagged everywhere as vulnerable.

It baffles me that NPM for so long couldn't replicate the same guardrails as Maven Central.


Replies

cluckindantoday at 2:40 AM

How does that protect against credential theft? MFA required to sign published releases?

show 1 reply