TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: Paid packages and package managers what faults do you see?

2 点作者 devrob超过 2 年前
Hi HN,<p>I had this thought this morning that in the same way you purchase a $0.99 song to 2.99 application on iTunes, what if you could purchase a CLI or application view homebrew?<p>I understand the philosophy around open source and the benefits therein with respect to the ability to pull any package from say NPM or Homebrew, but I was curious: with supply chain attacks and package malware becoming more prevalent (linked in comments), would creating an economic side of the package distribution help? I get NPM sells enterprise SaaS, but I was thinking on the client end.<p>For e.g.<p>Opt 1. Paid Homebrew &#x2F; NPM CLI<p>A paid package manager that analyzes the downloaded binary or package upon install. Basically &quot;anti virus&quot; package manager?<p>Opt 2. Paid packages<p>Instead of open source software developers seeking funding through open collective what if they could allow you to pay 1.99 via homebrew or npm to buy a license to the package some how?<p>I get the philosophical wrinkles in this, just curious peoples thoughts.

1 comment

devrob超过 2 年前
Some e.g. &#x2F; Links: - <a href="https:&#x2F;&#x2F;www.techtarget.com&#x2F;searchsecurity&#x2F;news&#x2F;252525968&#x2F;NPM-malware-attack-goes-unnoticed-for-a-year" rel="nofollow">https:&#x2F;&#x2F;www.techtarget.com&#x2F;searchsecurity&#x2F;news&#x2F;252525968&#x2F;NPM...</a> - <a href="https:&#x2F;&#x2F;github.com&#x2F;bitpay&#x2F;wallet&#x2F;issues&#x2F;9347" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;bitpay&#x2F;wallet&#x2F;issues&#x2F;9347</a> - Leftpad