Facebook Yarn's for your JavaScript package

General News

Summary

Its command line client provides more than five million developers with access to some 300,000 packages in the npm registry, resulting in about five billion downloads every month, at least by Facebooks measure. Facebooks Sebastian McKenzie, Christoph Pojer, and James Kyle in a blog post explain that the company has been using the npm client for years, but has run up against problems with package consistency, security, and performance. Earlier this year, Nikolai Tschacher, an undergraduate student at the University of Hamburg, presented a thesis titled "Typosquatting in Programming Language Package Managers." Doubts about the security of the SHA1 algorithm, used to compute checksums for npm package integrity, were raised several years ago in light of the crypto communitys warning that SHA1s days are numbered. Responding to those concerns in a Github issues thread earlier this year, npm software engineer Forrest Norvell dismissed the potential weakness of SHA1 because its not used for identifying the source of files.

Classifications

industries
InsurTech
applications
EduTech - learning

AskAI Classifications

Labels
Developer Tools DevOps Software SaaS

Linked Companies

GitHub, Inc.
$1M to $5M
Tilde Inc.
up to $1M