The idea being "I want the latest version, but not the absolute bleeding edge, I want something that has at least baked for a bit".
The idea being "I want the latest version, but not the absolute bleeding edge, I want something that has at least baked for a bit".
The idea is that for maliciously published packages like this (both deliberately in this case, and also when the maintainer's account is hacked) that not all packages that depend on this dependency will need the same length of N. Some users will want to pick it up right away, but some very conservative applications may want N to be much longer. It's basically the idea that alpha/beta users can be the canaries, but those who don't want to take any risk can hold back. Right now, unless you've got a lock file, essentially everyone is pulling the latest released version whether they want to be conservative or not.