TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: Paid packages and package managers what faults do you see?

2 pointsby devrobover 2 years ago
Hi HN,<p>I had this thought this morning that in the same way you purchase a $0.99 song to 2.99 application on iTunes, what if you could purchase a CLI or application view homebrew?<p>I understand the philosophy around open source and the benefits therein with respect to the ability to pull any package from say NPM or Homebrew, but I was curious: with supply chain attacks and package malware becoming more prevalent (linked in comments), would creating an economic side of the package distribution help? I get NPM sells enterprise SaaS, but I was thinking on the client end.<p>For e.g.<p>Opt 1. Paid Homebrew &#x2F; NPM CLI<p>A paid package manager that analyzes the downloaded binary or package upon install. Basically &quot;anti virus&quot; package manager?<p>Opt 2. Paid packages<p>Instead of open source software developers seeking funding through open collective what if they could allow you to pay 1.99 via homebrew or npm to buy a license to the package some how?<p>I get the philosophical wrinkles in this, just curious peoples thoughts.

1 comment

devrobover 2 years ago
Some e.g. &#x2F; Links: - <a href="https:&#x2F;&#x2F;www.techtarget.com&#x2F;searchsecurity&#x2F;news&#x2F;252525968&#x2F;NPM-malware-attack-goes-unnoticed-for-a-year" rel="nofollow">https:&#x2F;&#x2F;www.techtarget.com&#x2F;searchsecurity&#x2F;news&#x2F;252525968&#x2F;NPM...</a> - <a href="https:&#x2F;&#x2F;github.com&#x2F;bitpay&#x2F;wallet&#x2F;issues&#x2F;9347" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;bitpay&#x2F;wallet&#x2F;issues&#x2F;9347</a> - Leftpad