npm is growing hugely. It needs to sort out the domain space issue quickly.
And, it's not actually clear that a namespace would have been enough had a lawsuit actually been filed.
You may be right about the lawsuit.
I am not sure if I am being playful or not. I'll edit this post if I figure it out before the hour's grace period is up.
it's almost as bad as putting HTTP protocol in XML namespaces.
If you want namespacing to be tied to Internet domains then I want the right to take over your code after you forget to renew your domain.
at most you can borrow one.
What's the problem?
If not, or if we're going to put whatever we want in there anyway, then why hold to the idea it must correspond to a domain name anyway?
People advocating using a domain as the namespace get the same result, but the package namespace is tied to a domain, you have to have control of that domain, if you lose it, do you lose the namespace?
What if I don't own any domain, people are saying in that instance I should use io.github.myusername, why not just myusername? that way my code isn't tied to a platform I may not use in 5 years time.
I suppose that's it, a namespace is about my code, not about where the code is maintained or an external resource I may or may not keep access to, so don't namespace it in a way that ties it to such.
○ The dispute resolution policy minimizes disruption.
Transferring ownership of a package’s name doesn’t remove current versions
of the package. Dependents can still retrieve and install it. Nothing breaks.
Had Azer taken no action, Kik would have published a new version of kik and
everyone depending upon Azer’s package could have continued to find it.
It was abrupt unpublishing, not our resolution policy, that led to
yesterday’s disruptions.
http://blog.npmjs.org/post/141577284765/kik-left-pad-and-npmMy English reading comprehension isn't precisely the best, but I'm pretty sure this concern isn't addressed in the text you cited.
I don't see this concern addressed in their Package Name Disputes document at all: https://www.npmjs.com/policies/disputes
Perhaps they'd be delighted if you brought it up in the public forum they linked to at the end of the blogpost? https://github.com/npm/policies/issues/44
Or perhaps they would not. After all, my question is a very natural question to ask, and they don't seem to have given it any thought, as if they were ignoring a particularly big elephant in a small and cramped room. It seems deliberate to me. And, even under the unlikely assumption that it isn't deliberate, it says a lot about npm Inc's lack of empathy for their own users.
In any case, not being a JavaScript programmer myself, let alone an npm user, I can't bring myself to care enough to comment on their GitHub issue.
To make clear a package you published is your intellectual property, you're expected to use the "author" field in package.json; it's also common to mention your name in the README. The versions you published would continue to name you in the "authors" field and in the README, rather than someone else. Perhaps NPM thinks that suffices.
(You might do neither of those things, and the someone else might use your name to publish later versions of the package, or a random person might use your name to publish a completely different package. But these problems not affected by the policies being discussed, nor really have anything to do with NPM seeing as the same thing could happen on GitHub (someone else can publish a repo and attribute you as the author; also, will GitHub make perfectly clear that a repo you publish is your intellectual property, rather than someone else's?).)
My question doesn't apply to GitHub, because GitHub doesn't transfer your repositories to other people unless you tell it to.
It is a natural question, and I have asked it elsewhere in this thread (https://news.ycombinator.com/item?id=11385689). When control of package is handed over to a corp at version >=5.0.0, who exactly is responsible for releasing the bug-fix version 1.8.5? Point-releases are done all the time to fix security/bugs, so either NPM Inc didn't think about that scenario (bad) or decided not to address it (very bad).
It was abrupt unpublishing, not our resolution policy, that led to
yesterday’s disruptions.
http://blog.npmjs.org/post/141577284765/kik-left-pad-and-npmjust saying it twice from the same month doesn't make it less one sided.
And the current changes don't help with the pissed off developer scenario much. Because a pissed off developer can simply publish broken versions of packages instead of unpublishing them, and still break the world.
Actually my question (I'm parent) is also on the technical level, since I'm pessimistically assuming the lawyers will win everytime.
If Sandra renames her package (voluntarily or not) - will the old versions with contested name resolve correctly stickman v0.99? Or will they be gone forever? Will Stick Corp inherit management of the old versions? Is it a good idea? Who will manage point-release vulnerability upgrade - Sandra or Stick Corp? etc. There are a lot of questions relating to the original quagmire that NPM Inc is not answering.
The goal of Npm should be to insure that any software built using their tools enjoys uninterrupted historical continuity and progress. The technical challenge is as serious as the political complexity--exactly as it should be! Rash and sudden movements (yanking version, letting squatters snap up names) are undesirable because they do not honor the spirit of necessity:
Move only when necessary, and then move decisively, and always fight to ensure the historical continuity of the software. If people are confused, illustrate the precept in your actions and instruct the people!
it would be very rude to take the name 'stickman' from an author just because some big important webscale global internet of things unicorn multi-national 1000billion users app company has an app with the same name.
why can't they just call it stickman_app and not steal other people's land?
although we should also implement LVT to fix the landgrabbing issue
The reason kik was an issue isn't just that "Kik" is a trademark. It's that "Kik" is a trademark referring to a piece of software.
>Computer software for use with mobile devices, namely, computers, personal digital assistants (PDAs) and mobile phones for downloading, displaying, transmitting, receiving, editing, extracting, encoding, decoding, playing, storing and organizing text, sound, images, audio files and video files
The `kik` package was software that was used with other devices for other purposes.
KIK Interactive hasn't even been able to produce a specific Trademark that the `kik` package would have infringed upon.