Upcoming breaking changes for NPM v12
40 points by plasma 2 hours ago | 10 comments
Tiberium 36 minutes ago
I hope GitHub changes their vibecoded badges, what does RETIRED even signify in this context? Why does the preview have to be in ominous red?
replycute_boi 18 minutes ago
They should have added a 1-day age limit by default, so security scanners have some time.
replyTZubiri 27 minutes ago
Looks good? But doesn't this just change the compromise window from first installation to first run?
replysemiquaver 48 seconds ago
Ok? Not sure what a package manager can do about the fact that eventually you want to run the things you install.
replychristophilus 24 minutes ago
Better than nothing. That’s the same problem every package manager has.
reply
https://www.kb.cert.org/vuls/id/319816