3 ms·
Not to blame them NPM, they're great people, but I often get requests from random people going through NPM support to use an existing name (saying they will bum
by tjholowaychuk 8y ago
Not to blame them NPM, they're great people, but I often get requests from random people going through NPM support to use an existing name (saying they will bump major).
The centralized naming scheme is to blame here, it normalizes these "cute" names and users have demanded these since day one. They could/should have probably been scoped from the beginning, or people should just stop trying to capture fancy names.
I get tired of receiving emails about those kinds of things personally, you try to just ignore them, sometimes their request sounds reasonable but still, can those people be trusted, who knows.
- gregknicholson 8y ago> The centralized naming scheme is to blame here It would have been better just to use URLs, so if you see "npm install https://github.com/dominictarr/event-stream" https://github.com/dominictarr/event-stream" then it's clear you're trusting "github.com". (Yes, DNS is centralised. That can be fixed independently.)
- preommr 8y ago> NPM support to use an existing name (saying they will bump major). Sorry, could you please explain what this means? I keep seeing comments about bumping version numbers (e.g. the right9ctrl did some shenanigans with versioning).
- tjholowaychuk 8y agoAh sometimes you get people asking to use a name such as my "log" pkg in npm, but bumping from 2.0 to 3.0 so that dependencies aren't messed up. Assuming the person has no bad intentions I think it's a perfectly reasonable request. I ignored this particular request via email a few times, because I just really don't want to spend time dealing with Node stuff. You then get a request from NPM support asking the same thing, so I agreed to it, that's all it takes to get access to a package really. I think from now on I'm just going to tell people to come up with a different name, this wouldn't be a problem if the names were scoped by default.