Menu
Sign In Search Podcasts Charts People & Topics Add Podcast API Blog Pricing

Nicholas Zakas

๐Ÿ‘ค Speaker
455 total appearances

Appearances Over Time

Podcast Appearances

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

Because I have talked with folks who work on NPM.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

They're really dedicated.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

They're really smart.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

And the sense that I always get is just like, there's a really big backlog.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

There's not enough people to work on it.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

And so the stuff just kind of sits until there's an emergency.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

And my read on the response last year was,

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

And I have no inside knowledge of this at all.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

This is just my interpretation of what I was seeing, was that the things that they were rolling out were things that were probably already on their roadmap and just needed a little push.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

And this was the push of like, you know, running it up the chain and just saying, hey, these like three things we've been trying to get through for the past nine months, like this would actually really help with these attacks.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

So can we prioritize and resource these?

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

And that's why we got those.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

Again, just my theory, but it just, it seems like, and I gave this feedback directly to them too, that I just feel like all of this is attacking the problem from the wrong end at this point.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

Yeah, and I think that's exactly the problem, is that the NPM registry is a huge cost sink.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

It is wildly expensive to run, requires a ton of bandwidth.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

All kinds of companies are relying on it every day, running in their CI.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

And when the NPM...

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

company, NPM Inc., was running, they needed to sell because they couldn't afford to run the registry anymore.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

And it really was GitHub being like, hey, we are a haven for JavaScript developers.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

They didn't have to do that.