What I would like to see is all new unscoped packages being able to be installed/required by their scoped version by default. So if I create a package `coolThing` in npm entirely unscoped, it would be installable by doing `npm -i @Klathmon/coolThing` and by doing `npm -i coolThing`
That would let many of us to use the benefits of scoped packages without the package authors having to do anything. And it would be a big step toward going completely scoped at some point in the future.
Doesn't seem especially tricky.
Docker and go use URLs/paths for scoping, everything is scoped.
Java/Scala/Kotlin/XText/etc use reversed domains as scope.
And so on.
We can talk about how awful of an idea it was for npm to start the way they did all we want, but the reality is that they are in the position of unscoped packages being the "default" right now, and I'd love for them to get away from them in a safe manner.
- https://github.com/angular/angular
- https://github.com/rollup/rollup
- https://github.com/cherow/cherow
- https://github.com/hyperapp/hyperapp
Wouldn't we end up with a similar situation?
It also allows those orgs to group "sibling" or sub-packages under their main name. So I know that `@angular/cool-angular-plugin` is actually from angular.
But for the downside of "having to type a little bit more", I think it's more than useful enough at what it does fix/solve.
In other words, it solves between 0 and "a bunch" of problems for packages, and the downside is fixed at "needs to type a little more".
Even in the worst case, it's not that much harm, but in the best case could prevent exploits.
If one does the same on npm, it just transfers the namespace scarcity to 'scopes' themselves, with no real benefit.