4 ms·
I'm a fan of the approach of personally submitting projects to the repository maintainer (e.g. through GitHub issues), and having the maintainer personally appr
by eudox 10y ago
I'm a fan of the approach of personally submitting projects to the repository maintainer (e.g. through GitHub issues), and having the maintainer personally approve them.
It does raise the barrier to entry, but it would prevent typosquatting and regular namesquatting.
EDIT: Does any major package manager provide a "did you mean" functionality, offering a list of actual package names similar to what you typed?
- philjackson 10y agoThat's a massive burden on the poor person who has to ok the package - especially at NPM's scale, for example.
- yoo1I 10y agoWell, ideally you'd set up some sort of system where multiple people work on managing a repository, similar to maybe how linux distributions package applications and libraries.
- eudox 10y agoNPM's scale is the exception, rather than the rule.
- seldo 10y agoWe believe npm's scale is a direct result of having the lowest ceremony to publish a package. Turning the dial in the direction we did has pros and cons.
- burkaman 10y agoAPT does and others probably do too, but it obviously only gives suggestions when the package you entered doesn't exist.
- eudox 10y agoRight, it's only useful if you've prevented typosquatting. Which Debian has, because submitting a new package is a much more involved processes than sudo apt-get publish.
- akavel 10y agothen the maintianer must have perfcet sigth and never ovrelook even one tpyo :] and then also have perfect memory of all packages and notice that similarly named package is too (for some value of "too") similarly named to some already existing one... even if e.g. both are a correct dictionary word.
- tonyedgecombe 10y agoOr someone needs to approve suspiciously named packages.