Skip to content

Commit 0fbd443

Browse files
authored
Update Short-term-package-manager-wishlist.md
1 parent ffd4826 commit 0fbd443

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

Short-term-package-manager-wishlist.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,7 @@
11
# Short-term package manager wishlist (for Node.js/npm)
22

3+
_Originally made public at 2016-11-03._
4+
35
Do not treat this list as some outstanding problems or vulnerabilities on npm, Inc. side, it's closer to a personal wishlist of some hardening / transparency issues that would improve the overall ecosystem security. Also, good security is hard: some entries here require significant amount of work (some don't). The fact that they are not implemented yet is not a bug, vulnerability, or oversight, but keeping an open list of those still looks like a good idea to me. Also note that not all of this wishlist is targeted at npm, some of these could be implemented on the community side.
46

57
This is not post in favor or against npm, nor the intention of this post is blaming or offending anyone, or anything else like that. Note that my views could differ from other people views, and I also express some disagreement on some topics and the current way of doing things, but my only intention in writing this was to improve the current situation in the ecosystem and reduce potential risks. If you think that I chose incorrect language or am too harsh somewhere — just ping me over [email](mailto:[email protected]), IRC (ChALkeR@freenode), or [Gitter](gitter.im/ChALkeR). Also note that I am not a native English speaker, so I could have made mistakes somewhere.

0 commit comments

Comments
 (0)