Upcoming breaking changes for NPM v12
40 points by plasma 2 hours ago | 10 comments

efortis 5 minutes ago
this release fixes a vulnerability reported 10 years ago

https://www.kb.cert.org/vuls/id/319816

reply
Tiberium 36 minutes ago
I hope GitHub changes their vibecoded badges, what does RETIRED even signify in this context? Why does the preview have to be in ominous red?
reply
mort96 21 minutes ago
Hahaha that's amazing, just a big red "RETIRED" badge above their blog post? What the hell
reply
cute_boi 18 minutes ago
They should have added a 1-day age limit by default, so security scanners have some time.
reply
aniceperson 39 minutes ago
didn't know npm was owned by github.. well, that explains things...
reply
joeyhage 37 minutes ago
Most people know this but the _real_ reason it explains things is that GitHub is owned by Microsoft. Oh, and Microsoft moved GitHub to Azure
reply
BowBun 4 minutes ago
yes, since 2020
reply
TZubiri 27 minutes ago
Looks good? But doesn't this just change the compromise window from first installation to first run?
reply
semiquaver 48 seconds ago
Ok? Not sure what a package manager can do about the fact that eventually you want to run the things you install.
reply
christophilus 24 minutes ago
Better than nothing. That’s the same problem every package manager has.
reply