-
Notifications
You must be signed in to change notification settings - Fork 138
Open
Description
JSR is a new registry and there might (likely) be chances where people can preemptively register a well-known scope name on other registries, like npm. It could improve the supply chain security if JSR could prominently show the owner of a package.
As a reference, npm shows the owners on the right hand side of a package: https://www.npmjs.com/package/@opentelemetry/api. But on JSR, if I jump to a package page through search, https://jsr.io/@opentelemetry/api, there is no owner information on the first glance of the page. Lukily, the scope of https://jsr.io/@opentelemetry was not taken for a malicious intent. But it is still worrisome that there is no prominent information about the authenticity on JSR package page.
Metadata
Metadata
Assignees
Labels
No labels
Type
Projects
Status
Needs Triage