5 ms·
It feels odd that Github is deciding this policy. A high-impact package on another forge wouldn't be subject to the same constraint.
by freedinosaur 4y ago
It feels odd that Github is deciding this policy.
A high-impact package on another forge wouldn't be subject to the same constraint.
- tadfisher 4y agoGitHub owns and operates npm, so they certainly have the authority and ability to enforce it. I doubt requiring the same of packages hosted elsewhere is feasible.
- WorldMaker 4y agoDependabot and GitHub already scan Ruby Gemfiles and lock files and .NET's NuGet package references, among others. They already have the raw data to do it for a number of package ecosystems (and you can see that on repo pages if you go look for it). Starting with npm is clearly obvious because they also own npm, but I wouldn't be surprised if they set similar bars for other package ecosystems that they are aware that they host critical supply chains for.
- deleted 4y ago[deleted]