Doesn't happen to literally any other programming language (or maybe I just haven't paid attention to others)
Doesn't happen to literally any other programming language (or maybe I just haven't paid attention to others)
Personally, I think if you're not sure you want a package to be available publicly in perpetuity, you should maybe consider publishing it to a private registry. Even if NPM did allow developers to unpublish any package, there's nothing stopping me from downloading a tarball of your package as soon as you publish it, and hosting a mirror of it somewhere else.
As far as I can tell, NPM does not enforce any limitations on the license of published packages; I would not assume you can legally do this unless you have verified the package has been published under a license which permits such actions and which you are certain you understand.
I'm not a lawyer, but in my best judgment I see no reason to assume an NPM package can continue being used after it is taken down -- you need to actually evaluate the license it's published under to determine that. If I'm mistaken, I'd love to see a source establishing the contrary.
When you upload something to the internet it's there forever. The only way to ensure something is not on the internet is if you don't post it (and even then...). People are destined to learn this lesson over and over again.
I once saw a package on NPM that had a commercial license. It even had a link to its source on GH.
And a note that if you used the package you needed to pay up.
As has rust. https://blog.rust-lang.org/2022/05/10/malicious-crate-rustde...
NPM wants to have its cake and eat it too, which is the problem here. The solution is just to say that if you publish a package to NPM you give it the perpetual right to distribute it as-is, and then remove the ability for users to delete their packages at-will.
Yes, exactly!
Kind of unrelated, but I think it is important to remember that the left-pad was also ENTIRELY npm team's fault. You can't just take away a namespace from someone just because some startup like kik comes knocking.
Toyota does not have a right to my domain dot tld slash toyota The correct answer would have been npm to tell kik to pound sand.
npm has never fixed this grave error.
https://blog.npmjs.org/post/141577284765/kik-left-pad-and-np...
> We stand by our package name dispute resolution policy, and the decision to which it led us.
npm deserves to die.
So many issues arise from the fact that our UIs can’t do simple things on lists like folders (e.g. archive) and tags/notes.
The way PyPI does deletions is through "yanking," which is really a soft-delete mechanism. Yanking prevents usage of a particular package version for new resolutions, but allows fully-resolved versions to be downloaded. As a result, PyPI doesn't have the specific behavior that caused this (forbidding people from removing their packages because removal means hard-deletion).
I don't see these as serious contenders anymore.