Hacker Newsnew | past | comments | ask | show | jobs | submit | mladen5's commentslogin

I don't understand commercial aspect of large OSS like package managers but i was wondering for years why this was missing from npm. I think typosquatting was handled by npm last year but only after some popular miss typed packages started stealing developer creds.

The people building package managers are unaware of these problems going into it and it becomes extremely disruptive to start adding these things later on since your entire ecosystem is built on the assumption that they can do these things.

It's also shockingly controversial to suggest typosquatting suggestions. I made this suggestion ages ago for cargo, demonstrated that basic distance checks would have impacted <1% of crates over all time, and people still didn't want it.


I am grateful that he decided to mask himself as clown during this very informative presentation, it helps my sanity in check.

Especially after debugging performance issues on badly maintained nextjs app and not knowing most of this things.


Am i missing something or is there really a way to do this without doing any other additional steps?


I currently use the same thing and the issue is that you can't simply clone repo by copying url, you need to edit it each time. Not sure how does your GIT_SSH_COMMAND achieves in this case?


Most of conspiracy theories narrative was being controlled by Russia in recent years and now USA wants some of that. Probably with nothing to gain but conspiracy theories is all i hear from boomers these days.


And when you make it there is no reason fix anything


I don't like VS Code git integration, WebStorms (JetBrains) diff/merge tool with syntax highlighting is superior.


Debugger also much better in JetBrains products


I sometimes casually play Fortnite over nVidia Geforce Now via xDSL over wifi. And while i do entertain myself lag is hindering overall experience, at least in FPS games.


I love this so much. Its perfect tool for developers, i don't know how i didn't encounter this sooner, it exists for more then 5 years.


They requested me in an email to confirm my identity, i sent them requested IDs and never heard back from them.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: