
Arnout, 3rdEden
@3rdEden
Followers
2K
Following
2K
Media
278
Statuses
19K
Father of 2, Author of countless OS projects/libraries (Node.js, React(-Native), WebSockets, Frameworks etc) I shoot stuff online.
The Netherlands
Joined April 2008
Is there a way to just update all your @npmjs packages to require 2FA for **publishing**? As far as I can see it’s a manual process, and 1 package at the time. There has to be some automation for this right? Right??! Manually updating ~300 packages sounds like a lot of pain.
0
0
0
Semver was a mistake for dependency management as is evident by the recent #npmjs supply chain attacks. Its time package managers active start alerting maintainers when they specify ranges in their dependencies and suggest to go with fixed/pinned versions instead.
1
0
3