2 ms·
> If that is the case, then contributor's emails are being 'leaked' without their say-so or probably knowledge When you login into the NPM CLI it printed in al
by NoNameProvided 5y ago
> If that is the case, then contributor's emails are being 'leaked' without their say-so or probably knowledge
When you login into the NPM CLI it printed in all caps that the given email address will be public.
I don't like this either about NPM, but it's not like they are leaking in, they are upfront about it and warn you that the registered email address will be accessible to anyone in the package metadata.
- nighthawk454 5y agoYes, that is totally true. That's kinda what I was going for putting 'leaked' in quotes. It's not really leaked because the data is technically public. You can of course scrape it from say: https://registry.npmjs.org/react https://registry.npmjs.org/react However, it's been made significantly more accessible in a tool like this. NPM doesn't list it prominently in their UI anywhere (I believe). So the 'leak' is up-publicizing data outside of the control of the owner, and when other, intentional (and likely better) alternatives exist.