Skip to content

Two npm packages with different versions? #2

@ecker00

Description

@ecker00

Two npm packages with different versions? Seems sus

https://www.npmjs.com/package/@ampcode/svelte-check-daemon

Version: 0.0.6
Unpacked Size: 46.7 kB
Total Files: 12

https://www.npmjs.com/package/@eric.sampson/svelte-check-daemon

Version: 0.2.2
Unpacked Size: 44.9 kB
Total Files: 16

This used to work:

bunx svelte-check-daemon status
error: GET https://registry.npmjs.org/svelte-check-daemon - 404

I'm very concerned about supply-chain attacks, and this feels iffy

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions