And also by the experience of going through GitHub hosting a RubyGems server and all the fallout that happened there.
And also by the experience of going through GitHub hosting a RubyGems server and all the fallout that happened there.
1. It was introduced very late, meaning the community had already formed patterns of contribution around a flawed flat system. This is a problem of the flat system, not of the namespaced one.
2. It is still to this day entirely optional (for understandable backward compat. reasons). This gives namespaceless packages a misplaced position of authority over namespaced ones, which erodes the value of namespacing.
These are tough problems to get around if you start with a flat structure, but they really just outline the urgency of switching to namespaces for a relatively young project.
I wasn't arguing that npm's namespacing system is worse than their initial system, nor that their switch to namespacing was a mistake.
The current npm namespaced system, with flaws, is head-and-shoulders better than the previous flat system.
You're saying you did "look and learn". If by that you mean you looked at the end product (npm's is seriously flawed) without looking at the journey to that product (npm's is still a huge improvement over what they started with), then you're not going to learn much from that kind of "looking".
I highlighted Composer/Packagist in a sibling comment as a system you should look and learn from (w.r.t. namespaces).
Choosing to only look at flawed systems that started flat seems like you're just being selective to support your own thesis.
Not effortless, but not necessarily very costly either.
Don't those package registries all suffer from not having namespaces? RubyGems in particular [1].
[1] https://thehackernews.com/2020/04/rubygem-typosquatting-malw...
However, typosquatting is an orthogonal problem to namespacing, you can still typosquat a namespace.
This is not the first time typosquatting attacks of this kind have been uncovered.
Popular repository platforms such as Python Package Index (PyPi) and GitHub-owned Node.js package manager npm have emerged as effective attack vectors to distribute malware.
"Orthogonal" suggests no connection but what I see above is a list of package managers that don't have namespacing.
I stated my reasoning in my comment: you can typo squat a namespace, just as easily you can any identifier. I don't see any inherent difference between the two.
correlation does not equal causation.
how is it not apparent that typosquatting is possible regardless of whether namespacing is in play?
for example, URLs are namespaced, and are the classic example of typosquatting: https://en.wikipedia.org/wiki/Typosquatting
People can just have maliciously typeo-d namespaces
Actually you could argue it's worse since people tend to pay more attention to package names rather then namespace names