



















I'm sure everyone is aware by the mass infection of orphaned packages (around 1700) that have been targeting developers, which is because orphaned packages can be "adopted" and be re-maintained by another maintainer to keep it active. Only issue is that this does way more harm than good, so why let this even be an option to begin with? Why let anyone adopt a package thousands have installed on their computers to be at the mercy of the new maintainer? If they want to continue a package let them just fork it or something don't hand them control over the package that many users have.
This is what i think at least, so correct me if I'm wrong.
i already reported it thank you
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。