Earlier quoted context omitted.
> Extensive name squatting, to the point that virtual no library uses the obvious name, because someone else got to it first. Maybe the obvious names should have been pre banned. But I don't see the issue with non-obvious names either way you're going to have to get community recommendation/popularity to determine if brandonq/xml is better or worse then parsers/xml
In ASP.NET land, I regularly work on projects where there is an informal rule that only Microsoft-published packages can be used, unless there's good reason. You don't want to be using Ivan Vladimir's OAUTH package to sign in to Microsoft Entra ID. That probably has an FSB backdoor ready to activate. Why use that, when there's an equivalent Microsoft package? When any random Chinese, Russian, or Israeli national can…
I think we need to encourage a culture that package managers are our shared garden and we must all help in the weeding.