Earlier quoted context omitted.
I couldn't help but think the same thing. Seems like an incredibly immature way to handle it. He could have easily set an end date and state nothing will be maintained beyond that date. It's not a good look.
marak has a documented history of mental illness and downright odd behavior. Talented dev and troubled individual. There's a pretty concise video covering what went down with some history here: https://www.youtube.com/watch?v=R6S-b_k-ZKY
Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps
651–660 of 1001 posts
Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps
#652Earlier quoted context omitted.
no its a criminal act. crashing RANDOM servers that you DONT know what they do is not a protest.
Your argument could be used to describe any software defect, whether malicious or accidental. Open-source code is mostly not produced with any knowledge of downstream servers; that's the responsibility of the server owners. The software developers also have a responsibility to ensure they trust the author and are okay with the code they are importing into their own projects.
Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps
#653Here's my $.02: Packages are literally remote code exec vulns in the hands of package authors. At the very least, it takes them under a minute to break your app, simply by deleting their package. Read the article. This is not the first time it's happened, and it's not going to be the last. [0] I write backends (mostly in PHP, although not exclusively), and I release a lot of my code under libre licenses. But I don't…
But here we are, 10 years in, with nobody giving a damn about semantic versioning.
Life could be so much easier with an actual package manager that isn't just some git clone replacement.
Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps
#654It's time for someone to make a Redhat, but for "safe" open source software libraries. My big enterprise would sign up for it in a heartbeat. We'd pay for access from an alternative NPM registry where everything is at least semi-vetted - someone at least looks at diffs before new versions get updated and made available. Sure, the "safe" repo wouldn't have as nearly as many packages as the main NPM repo, but if it had…
Use a language where you don't need to pull in 100 dependencies to create a useful application/service.
Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps
#655Earlier quoted context omitted.
> I think Marak is teaching an important and principled lesson here. What lesson is that?
Quoted post unavailable.
Which trillion dollar corporations are these?
A quick google says "Apple, Microsoft, Alphabet, Amazon, Telsa, Meta, NVidia, and Berkshire Hathaway" are the the only trillion dollar companies
Except for the last one all of those companies give back vast amounts of open source support. All you using VSCode for free, that's Microsoft's payback. Oh, and Microsoft pays for NPM hosting and github, also Typescript, C#, F#, .NET. Hardly not giving anything back. Apple gives Swift, Clang, LLVM, Webkit to name a few. Alphabet, Go, Chrome (which also means Electron on which VSCode is running), Android, and plenty of others. Meta provides React, Redux. Not sure what open source Tesla gives back but they have given their patents (https://www.tesla.com/blog/all-our-patent-are-belong-you). Nvidia gives away tons of open source as well (https://developer.nvidia.com/open-source)
Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps
#656Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps
#657Earlier quoted context omitted.
> It's his code to break if he wants > I don't understand why If he can break his code because he is the owner then shouldn't the same reasoning apply for Github suspending the account?. It is their website and their rules. Keep in mind Github owns npm and the author has published a malicious package to npm which has 20 millions of downloads so I'm not surprised.
For some reason, people are adopting the ideologically inconsistent position full property rights to the dev, but no property rights to Github.
Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps
#658It's time for someone to make a Redhat, but for "safe" open source software libraries. My big enterprise would sign up for it in a heartbeat. We'd pay for access from an alternative NPM registry where everything is at least semi-vetted - someone at least looks at diffs before new versions get updated and made available. Sure, the "safe" repo wouldn't have as nearly as many packages as the main NPM repo, but if it had…
You really need an organization which sponsors and directly hires coders that are maintaining critical infrastructure.
(Of course the npm world is a bit insane where stuff as trivial as leftpad can be critical infrastructure. Don't really think someone needs a $200k/yr salary to maintain just that)
There's an interesting bit of social psychology here where the top reaction to this isn't "lets try to sort out how to pay all the people who are doing all the free work" (and I'm really thinking more the log4j and openssl people and the whole broader ecosystem problem this highlights) and instead it is "how do we keep being exploitative and just outsource the hard job of vetting everything?" I'm pretty sure Google will probably get some AI people onto the problem though, there's clearly a business model there.
Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps
#659Earlier quoted context omitted.
Why is that scary? If you do bad things, you're going to get banned. This guy abused Github to distribute malicious code to thousands of projects. If losing your Github means losing your projects, that's on you for being lazy/irresponsible with them. Git is already decentralized, and anything important should be cloned on something you own.
What's actually malicious about the code? It's an infinite loop that logs to stdout. Sure, it's not what the library is supposed to do, but is it malicious code?
Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps
#660It's time for someone to make a Redhat, but for "safe" open source software libraries. My big enterprise would sign up for it in a heartbeat. We'd pay for access from an alternative NPM registry where everything is at least semi-vetted - someone at least looks at diffs before new versions get updated and made available. Sure, the "safe" repo wouldn't have as nearly as many packages as the main NPM repo, but if it had…
If you want to use this distro in your own company with full time support and continuous upgrades by yours truly, my yearly salary will be 220,000 USD, please--not counting any donations you decide to make to individual software authors to ensure your use case is covered by their software, as the above amount covers only my personal salary and considerable expenses.
A large discount is potentially available should other corporations avail themselves of this opportunity and also help cover my salary and expenses. Contact me at [email redacted].
I'm not holding my breath that anyone will take me up on this opportunity, so this distro will just have to remain for my exclusive use only, I'm afraid.