# Learning From npm's Rough Few Months

DevFeed: [Learning From npm's Rough Few Months](<https://devfeed.tech/articles/learning-from-npm-s-rough-few-months-36865.md>)

Original publisher: [Read original article](<https://shostack.org/blog/learning-from-npms-rough-few-months/>)

Author: Adam

Published: 2017-08-15T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [npm](<https://devfeed.tech/topics/npm.md>), [Package manager](<https://devfeed.tech/topics/package-manager.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>), [Security](<https://devfeed.tech/topics/security.md>), [reusable code](<https://devfeed.tech/topics/reusable-code.md>)

Tags: [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [npm](<https://devfeed.tech/tags/npm.md>), [reusable-code](<https://devfeed.tech/tags/reusable-code.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

This commentary examines npm's difficult recent period, what npm and other package managers could do, and what policy lessons may follow from treating package infrastructure as critical infrastructure.

## Source excerpt

[no description provided]