5 ms·
Agreed this would be nice, though this layer of complexity introduces a bigger attack surface for bad actors. They could try to get their modules listed as depe
by colinmcd 6y ago
Agreed this would be nice, though this layer of complexity introduces a bigger attack surface for bad actors. They could try to get their modules listed as dependencies of popular projects to piggyback on their downloads. On the flip side there are some low-level tools (say, the `stylis` CSS autoprefixer) that are almost never used in their "raw form" but are the backbone of several massively popular projects. It's a tricky balance.
- JimDabell 6y agoIs this really a concern though? In this situation, adding a dependency to your project means making a decision to divert some of your funding to them as well. It gives an incentive to avoid adding unnecessary dependencies.
- NameDoesntExist 6y agoWorkaround: fork all your dependencies with minimal if any changes and add them back to your main project. This allows you to cut-off the trickle-down funds in bad faith.
- OJFord 6y agoIf you're willing to do the extra maintenance of keeping them up to date (or else on the hook for their issues) ... maybe that's 'ok'? I don't mean that it's a service worth paying for, just that maybe it doesn't seem like it's worth the extra (presumably minor) cut of initial donation and people wouldn't really do it (more than once / for long / on a big project with significant donations) anyway.