Hacker News new | past | comments | ask | show | jobs | submit login

> Why even let people publish packages if they're not meant to?

I don't think GP even so much as insinuated in their post that people aren't meant to publish packages in general.




The argument was: only packages which are good enough for production use ought to be published on official package repositories. This allows people to assume that all packages on the repository are stable, well maintained, good quality software without manually verifying each dependency.

So why even let random people sign up a developer account and publish packages? Maybe they need a separate curated "serious packages only" repository.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: