Open Source Insights
deps.dev
deps.dev
To the rest of the HN crowd, I would like to propose a game. You suggest how many months it will take until this will end up here:
The one closest wins.
Here goes my bet : 24 months
See you all in 2 years or sooner...
"Dependency Graphs for Open Source packages" or something
If the exercise is to capture / mediate GPL2/3 dependencies, then having results missing kind of defeats the purpose.
one of the many poor decisions of npm: being completely blase about privacy.
You can see the Collaborator's NPM profile, where _they_ can set handles to contact them at. You can also get to their GitHub profile where they also can set handles to contact them at. If the tool made it easier to see those, then great.
These emails don't appear to be directly listed on NPM's website. Or correlated with Github/NPM profile. My guess is they're surfacing the email associated with that user's NPM account? Which is not otherwise obviously listed. And the only way you could control it is by also affecting who is an owner of the NPM project itself.
If that is the case, then contributor's emails are being 'leaked' without their say-so or probably knowledge, and without any particular way of managing it. Meanwhile they've already listed perfectly good ways of being 'reachable'.
When you login into the NPM CLI it printed in all caps that the given email address will be public.
I don't like this either about NPM, but it's not like they are leaking in, they are upfront about it and warn you that the registered email address will be accessible to anyone in the package metadata.
However, it's been made significantly more accessible in a tool like this. NPM doesn't list it prominently in their UI anywhere (I believe).
So the 'leak' is up-publicizing data outside of the control of the owner, and when other, intentional (and likely better) alternatives exist.
So at least it's on NPM and not this new thing.