Menu
Sign In Search Podcasts Charts People & Topics Add Podcast API Blog Pricing

Jared

๐Ÿ‘ค Speaker
5113 total appearances

Appearances Over Time

Podcast Appearances

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

And I wonder what happened there.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

Like what, why, but, um,

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

You mentioned Volt.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

That's another one that's been up and coming from longtime JS ecosystem people, Darcy Clark and friends, and then backed by a lot of people who have been around the ecosystem forever and have benefited and had issues with NPM over the years.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

Is Vault been manifest?

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

Is it still becoming a thing?

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

Is it a viable option?

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

Because eventually we can't make GitHub do anything.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

And so if they're not going to do anything, we can continue to tell them they should and try to convince them.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

But having some other alternative, which I was hoping JSR would become, would be at least somewhere you could put your efforts into and say, let's all do this instead.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

And it would be grassroots and it would be a lot of work.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

And I understand there's

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

billions of things being downloaded every month off of NPM.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

But if the package maintainers had somewhere to point people and say, you know what, for new versions of ESLint, you got to go here, you know, put it in your post install script.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

This is an old version of ESLint for the new version.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

I'm only publishing on this other platform.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

Go read my blog for the reasons.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

If you can get the top 100 packages for maintainers to do that, you could probably make a dent.