Is that how people use NPM?
Also maven central does NOT support unpublishing of binaries. So if you have version 1.2 of something and you have scanned it once for vulnerabilities, it should always be the correct one. Nobody can publish again 1.2 in the central repo
Unpublishing within those companies is usually not allowed, in the official npm registry you can only unpublish within the first 24 hours of publishing, after that you need to request it by email.
If that was the case for everybody, then left-pad would not have caused a problem for anybody. People would not notice anything wrong with their builds. The amount of github comments where people say that their production build just broke because of a missing package implies that people are NOT using NPM with a local registry
>in the official npm registry you can only unpublish within the first 24 hours of publishing
I don't believe this to be the case https://news.ycombinator.com/item?id=16087024
https://status.npmjs.org/incidents/41zfb8qpvrdj
The fact that 9 packages could be "published over" _after_ the left-pad fiasco, shows lack of attention.
Tools should try to foster good practices, instead of worsening bad ones.