External Publication
Visit Post

Fork `basement`? As `baseplate`?

Haskell Community [Unofficial] February 19, 2026
Source
i read through all the commentary, and this honestly smells to me as somewhat intellectually dishonest. “oh my package needs updating but you need my permission to use the unique identifier i own? your package manager should just be better and not let someone cause that problem.” “i don’t want to be responsible for supply chain attacks if i give someone else the commit bit. also, there shouldn’t be trustees at all who would take this responsibility.” the whole thing is more FUD and aesthetic theorycraft than practical concerns. definitely agree this is a package takeover loophole. Package versioning exists and is the solution to his problem. Future version could easily have different maintainers etc - his older versions are still sitting there unscathed by this would-be development.

Discussion in the ATmosphere

Loading comments...