Earlier quoted context omitted.
I'm sure 6.6.6 threw a spanner in the works for folks who didn't lock deps. Not great. But Marak's one of us. This feels a lot bigger than that. I don't have a direct line on what happened to him, or where it took him, mentally or otherwise. But the hints so far aren't great. To one of us. I think the responses from the platforms---GitHub, OpenCollective---get folks thinking, whether they feel it that way or not.
What GitHub did was completely reasonable. They mitigated harm to their users on their own infrastructure and property. They did not change his code. They just took down his malicious code that caused harm. The vast majority of people on HN would never purposely harm strangers. Most of these strangers are fellow developers ie “Us”
I'm sure the people who got burned on builds had bad days. It's not fair to blame them entirely, for not locking deps. It is fair to point out this isn't the first time builds have broken, with npm or other repositories. Nor the most widespread in effect. Does this count as a crisis?
If anything, I suspect a crisis of faith. Seeing bad things can come of `npm install`, and those bad things might be intentional or just plain weird, instead of well intended but accidental, can make people anxious. Publishers to npm don't just disappear or malfunction. Their faults can be byzantine. But there are defenses against them.
On the maintainer side, like it or not, we all have an editor when it comes to publishing on GitHub. But it matters how invasively that power gets wielded, and how heavy-handed it's perceived. This episode suggests to me that the threshold for intervention in the name of user interest's pretty low.
That's based on the information I have. Perhaps GitHub will share more on the blog.