Nicholas Zakas, creator and long-time maintainer of ESLint, says GitHub's response to npm's security problems is not enough. In a post titled 'How GitHub could secure npm,' Zakas lays out concrete alternatives GitHub has not taken. He argues that npm, a registry underpinning virtually all JavaScript development, is being treated as an afterthought by the company that owns it.
The episode goes beyond the blog post. Zakas calls out JSR, Deno's JavaScript registry, as a weak alternative, and the conversation surfaces a broader pattern: critical open source infrastructure owned by large companies tends to stagnate. The specifics of what GitHub could do differently, and why it has not, are where this conversation earns its runtime.
If you ship JavaScript, this is your supply chain. Zakas is not speculating. He is the person who built one of the most widely deployed linting tools in the ecosystem and has watched npm's governance up close. Read the linked post, then listen to understand what is missing from it.
[READ ORIGINAL →]