GitHub's npm gave away a package name while it was in use, causing rethink
When it comes to ownership then details count
Last December, GitHub recognized that it hadn't revisited the dispute policy for npm packages since acquiring NPM in March, 2020, and in February this year, it suspended transfers of abandoned packages until it could come up with a system that's fair, consistent, and enforceable.
The Microsoft-owned company did so because Andrew Sampson, CEO and co-founder of streaming app Rainway, showed that npm's process was none of those things.
Sampson and other contributors created an open source, cross-platform serialization format called Bebop to support the Rainway app. To ensure the chosen name remained the same across multiple programming languages, they proceeded to register the Bebop package name at various package registries like .Net's NuGet, Rust's Cargo, and Dart's pub.dev.
"After a few weeks, if there's no resolution, we'll sort it out," the now removed dispute policy explains.
Sampson emailed the listed address, got no response, and four weeks later was rewarded with a note from npm giving over control of the Bebop name.
Github's npm team shouldn't have done so because the registry had the wrong email address for the individual who had registered Bebop and had been using it for more than eight years.
"As it turns out, the package was not abandoned," explained Sampson via Twitter. "[Zach Kelling] published it over eight years ago and used it consistently in that time."
According to Sampson, none of the emails associated with Kelling's account received the name inquiry and the email address produced by the command
npm owner ls bebop wasn't associated with the package.
"Zach only noticed the ownership had been taken away from his account because an update failed to publish," said Sampson.
- Security warning deluge from 'npm audit' is driving developers to distraction
- GitHub stuffs $1m in Stanford Law School's pocket to provide free legal advice to DMCA-hit developers
- About half of Python libraries in PyPI may have security issues, boffins say
Sampson said Kelling opened a ticket with npm support and was told the name would not be returned, but was offered a GitHub Pro subscription and a $100 credit for GitHub merch "for the inconvenience."
"We take our role as stewards of the registry very seriously," a GitHub spokesperson said in an email to The Register. "We are not currently accepting dispute requests to 'adopt an abandoned package' as we re-evaluate and update the overall dispute process, which we’re tracking in our Public Roadmap."
Kelling did not immediately respond to a request for comment.
All wrapped up
Sampson personally ended up compensating Kelling for the name after getting in contact. And Kelling subsequently renamed his original Bebop package "bebop-cli."
Sampson nonetheless expressed concern that the NuGet community is currently trying to implement a similar process for taking over package names and fears it will have the same problems.
"Package adoption creates new avenues for compromising supply chains – registries should not be facilitating it," was the warning. "If a package transfer does need to occur, then the only method to do so should be the owner doing it. The registry itself shouldn't have the ability."
In an email to The Register, Sampson expressed sympathy for GitHub and npm, acknowledging package management and registry operation are both difficult.
"I think mistakes are inevitable at the scale of something like npm," Sampson said. "That being said, their response to the developer that was impacted by their mistake was pretty awful. That is why we ended up paying him $5,000 because I understand that for a developer time is their most valuable commodity, and the undue stress and disruption caused by their mistake likely hampered them for a few days."
Sampson expressed pleasure that npm suspended its transfer process as a result of the incident and noted that the support rep in communications dealt with mentioned that previous incidents of this sort had already prompted changes in npm's processes.
Transfers of control over package names at npm have proven problematic in the past, as the 2019 PureScript incident demonstrates. Other package registries have encountered similar issues.
The Java ecosystem, like some others, has dealt with potential name conflicts through hierarchical namespaces. For example, a Java program will reference
com.example.library_name.package_name, as opposed to just
package_name. This offers an obvious way to avoid identical package names.
But that convention isn't adopted everywhere and in programming ecosystems that accommodate flat namespaces like "bebop," names accrue brand value as they become popular or just because they're short and memorable. That has the potential to incentivize abuse like name squatting and to encourage developers to take steps to capture, control, and perhaps speculate on "great names."
"I think it is a hard problem to solve," said Sampson. "Should a package name be lost forever simply because someone registered it over a decade ago and never actually used it? What happens if the owner of a popular package dies and they never assigned other primary contributors, is a fork now forced by the community? There is a lot of nuance involved here. People much smarter than me will figure out a system that works – that is the beauty of open source." ®