Replies: 4 comments
-
|
💬 Your Product Feedback Has Been Submitted 🎉 Thank you for taking the time to share your insights with us! Your feedback is invaluable as we build a better GitHub experience for all our users. Here's what you can expect moving forward ⏩
Where to look to see what's shipping 👀
What you can do in the meantime 💻
As a member of the GitHub community, your participation is essential. While we can't promise that every suggestion will be implemented, we want to emphasize that your feedback is instrumental in guiding our decisions and priorities. Thank you once again for your contribution to making GitHub even better! We're grateful for your ongoing support and collaboration in shaping the future of our platform. ⭐ |
Beta Was this translation helpful? Give feedback.
-
|
Adding another concrete false positive and a related tooling request. I tried to publish the unscoped npm package I contacted npm support, and they confirmed that when an unscoped name is blocked by the automated name-similarity safeguards, support cannot manually override or allowlist the unscoped name. I have published the fallback scoped package at https://www.npmjs.com/package/@favoyang/planrock, but the desired CLI UX is Two improvements would make this much easier for legitimate package authors while preserving typosquatting protection:
The current flow forces authors to discover this only at publish time, often after repository, documentation, package metadata, and release automation are already prepared. |
Beta Was this translation helpful? Give feedback.
-
|
Yeah. |
Beta Was this translation helpful? Give feedback.
-
|
just chiming in since i left a comment on @ArgusPano's related discussion ,,
|
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
🏷️ Discussion Type
Bug
Body
The package name similarity detection lists completely unrelated names that would never typo.
I'm listing this package name as an example because it's one I don't want:
I've tried a bunch of package names and can't publish them.
Similar sentiment: https://x.com/_developit/status/2033015833660674190
Beta Was this translation helpful? Give feedback.
All reactions