How one developer just broke Node, Babel and thousands of projects
theregister.co.uk
theregister.co.uk
It seems to me that once published to NPM there should be some process for deprecating a module that is then "unpublished"... rather than just breaking every module that uses it as a dependency instantly.
They could spawn automatic emails to all dependent module owners about the hard deprecation and give them 7-30 days to replace the module before it's removed from the package ecosystem.
A module for padding the left of a string?!
Used by big projects like Babel?!
NPM takes down a modules without asking the dev
NPM republishes another module without asking the dev.
Then the whole NPM3 mess (unrelated to this article)
If have the feeling those people there have no clue whats on.
One mechanism that could fix that problem, and the left-pad problem is to allow defining a package substitute in your root package.json file. Then you could swap out the dependencies of your dependencies.
packageReplace : [{source_name: 'left-pad', source_version: '1.0.1', target: 'https://github.com/foo/bar' }]
...something like that