4 ms·
I have a question: Is it the responsibility of the package manager to keep users safe? By that, I mean, if there was a security vulnerability that the maintain
by tcd 7y ago
I have a question:
Is it the responsibility of the package manager to keep users safe? By that, I mean, if there was a security vulnerability that the maintainers refused to fix, what would the process be?
Should NPM refuse to install packages marked as deprecated, perhaps after a certain age of deprecation (say, 6 months)?
Comparing this to the browser where I believe it is the expectation Firefox, Chrome, Safari et al to keep users safe, by updating automatically if an issue is discovered.
- hombre_fatal 7y agoI don't see why NPM should be so heavy-handed as to prevent installation of deprecated software. It already shows you a warning. I think it's a good example of when systems over-act on information they do know (a developer has marked their software as deprecated) in ridiculous contrast to all the information they don't know (99% of developers not even bothering to deprecate their package when they abandon it).
- thrower123 7y agoAre they being paid to do so? If not, then you've got to do your own looking of the gift-horse in the mouth, and not expect the giver to do it for you.
- SahAssar 7y agoIt is the responsibility of the developer who added the dependency, or the person who reviewed the PR that added the dependency. If neither of those are around it is the responsibility of the person who took over either of those responsibilities or the person who now maintains that package. If that person isn't around then it is unmaintained, and should not be used. If that sounds complicated it is because it is. In any given package you might have 1-100ish people with responsibilities, but they also have sub-responsibles that they might not know about. The package management system has no responsibility except to serve the exact version of the exact package you requested. If you expect anything more from them you are not looking for "package management" and npm is probably not the right place to look. This is one of the reasons I try to not have transitive dependencies in JS projects.