4 ms·
No. I would use domain as a vanity pointer and a permanent account as the source of truth that clients use to download packages. You have to assume the domain
by ryan29 3y ago
No. I would use domain as a vanity pointer and a permanent account as the source of truth that clients use to download packages. You have to assume the domain can be dropped and re-registered by a bad actor, so a permanent account with proper package signing is really the only way to ensure you're not getting packages that are the result of an account takeover.
All a domain based namespace really does is help to get rid of impersonation and the confusion causes by squatting and mismatched namespaces everywhere. I think it helps in evaluating trustworthiness the first time you add a package to a project, but you still need package locking and signing to ensure you're only getting packages from the person or organization you've trusted.