What are the chances it's a placeholder for malicious/trojan code intended to steal Libra coins? (c.f. the event-stream backdoor[2])
What are the chances it's a placeholder for malicious/trojan code intended to steal Libra coins? (c.f. the event-stream backdoor[2])
Should really be:
https://crates.io/crates/someorg/libra
https://crates.io/crates/facebook/libra
People like unqualified names because it's slightly cute, though.A) Packages can change owners without changing names (and breaking downstreamers)
B) It encourages creative names, rather can calling something myusername/http, you have to give the package a real name like hyper, express, curl, etc.
Who wants this?
Seems like this is survivorship bias. All of the common names get squatted by people who never push code, and then anyone who's actually going to build something will need to pick something unique.
Reqwest is more popular than request, for example. It's not exactly what most would expect, and if you search "request" you get the much less popular crate.
I don't know. I'm unconvinced that this is a meaningful metric, and I worry more about typosquatting/ malicious dependencies, which, to my knowledge, crates.io does almost nothing to proactively deal with.
Usually, orgs won't be comfortable with this..
(B) is brilliant... We all know what EC2 and S3 is... If Amazon had just called these services for: compute and storage, there wouldn't be any brand.
Branding makes things easier to search for and to talk about.
All this said, these downsides might be worth it
npm install burrito doesn't.
Crates.io has all sorts of other problems where it assumes good faith.