Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Ask HN: Why would or wouldn't you distribute modules on GitHub instead of NPM?
3 points by benologist on Aug 26, 2019 | hide | past | favorite | 2 comments


The biggest thing to me would be if they offer a verifiable way to tie the modules offered in GitHub's package manager to the source hosted in GitHub. NPM's had a lot of weird issues with package takeover or malicious insertion, and GitHub, being where the source code generally is, has a real opportunity to address that.


I'm not sure why we still use NPM. It's a total mess.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: