Menu
Sign In Search Podcasts Charts People & Topics Add Podcast API Blog Pricing

Nicholas Zakas

๐Ÿ‘ค Speaker
455 total appearances

Appearances Over Time

Podcast Appearances

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

They didn't need it.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

Because at the time, I think it was just a few months earlier, they had actually announced their own NPM-compatible registry built into GitHub, which is still there, but doesn't seem like people use all that much, except maybe as private repos inside of companies.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

So they didn't really need to buy NPM.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

And I don't know who would have bought it otherwise.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

But at the same time, it's like if you adopt a dog, you should take care of the dog.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

Well, so my counter to this argument, which I completely understand, is that all it takes is one attack that costs people millions of dollars in some way or costs a company millions of dollars.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

before this becomes not just a like, oh yeah, hey, we're keeping it alive, but you know, like there's a responsibility because if you don't take care of that dog, it's gonna start biting everybody in the neighborhood.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

And then you're looking at not just

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

Like, oh, this is, you know, it tarnishes our reputation, like it doesn't look good.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

Now you're looking at like significant financial repercussions.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

And, you know, I'm sure there's stuff in the terms of service that says that they can't be sued.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

That's what I was going to ask.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

But, you know, there still might be some big company out there that's like, hey, you know what?

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

We're just going to try it because we're a multi-billion dollar company and we have the money to throw at lawyers.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

We'll give it a shot and see what happens.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

But this has been my concern for several years now is that