The owner of several 1 letter NPM packages
npmjs.com
npmjs.com
For example I contacted GitHub because I wanted an organization name for a company I'm registering in 2017. Their support looked at the organization, which had zero public or private repositories, told me they went beyond a time period of zero activity in which their name could be reclaimed by someone else and I got it (and no they didn't tell me the time period, it was just a vague statement regarding it).
NPM should look at these and if they've been empty for X amount of time, remove them. Now the problem is controlling new squatters so they may need to offer a more complex solution when a name returns to the pool but I think it needs to be done (I know names don't typically return to be re-used in NPM but if they're removing them for squatting I think they should).
In regards to length, well, that's how namespacing works. Although that is likely part of what has contributed to it receiving less traction.
I don't think that's even close to being a satisfactory call-to-action.
Whenever I've picked a name for a project, I've always generated them by combining words together with hyphens. If I realised that I could take over package names that were being squatted, there are many times I would have done so.
And actually... "Package name disputes" are mentioned in different ways within 5 of the 6 links in the "Legal stuff" section, so I am pretty sure that it's just for lack of reading/searching, not because they are actively trying to hide it.
Clicking on this button should start a partly-automated, formal process and not require writing an email or manually soliciting contact with the original owner. This process can then be managed by NPM, who can stop relying on hearsay over whether these disputes are being resolved.
The only reason to bury this within the 'Legal Stuff' section is when you erroneously assume that this action is likely to be a legal issue and informed by patent, trademark or copyright law.
The current solution is cumbersome, not pointed to sufficiently, and likely to become progressively worse as the NPM ecosystem expands. I'd bet many NPM users aren't familiar with this resolution process. (Apart from those that remember the kik and left-pad debacles. "hahah, you’re actually being a dick. so, fuck you. don’t e-mail me back.")
All I'm saying is that this process needs to be clear, structured and measurable.
If NPM was doing a good job here, this HN post would never have been upvoted.
NPM is also improving, AFAIK they were really messy in the beginning and now getting better and better. This issue came up as I mentioned in other places because of an initial error that has been corrected long ago (case-sensitive package names). So hopefully someone will see your comment and do something about it.
As for why we don't automatically/proactively handle squatting: it's a very thorny problem. Whatever minimum standard we applied to count as "not squatting" could be trivially discovered and gamed, eventually resulting in people who wanted to squat on a name just publishing a copy of `express` or something to that name as a placeholder.
Relatedly: you can report offensive, or deliberately confusing package names ("typosquatting") and we will take those package names down permanently.
Stats
64,840 downloads in the last day
1,360,036 downloads in the last week
4,980,362 downloads in the last month
Why is this package so popular?Shouldn't NPM be able to determine the difference between packages that are in use and package squatting?
Edit: Apparently there is a Github issue for this[1]
[0]: https://www.npmjs.com/package/d [1]: https://github.com/npm/registry/issues/38
Edit: further evidence: when you mistype a name in lowercase such as https://www.npmjs.com/package/aaaaaaaaaabbb it gives you instructions on how to create the package with that name; however when you do with a name with a capital letter such as https://www.npmjs.com/package/aaaaaaaaaabbB it just shows a 404
Google searches would be so bad.
I am writing a blog post about the topic as well, I think NPM is doing a great job here.