HACKER Q&A
📣 devrob

Paid packages and package managers what faults do you see?


Hi HN,

I had this thought this morning that in the same way you purchase a $0.99 song to 2.99 application on iTunes, what if you could purchase a CLI or application view homebrew?

I understand the philosophy around open source and the benefits therein with respect to the ability to pull any package from say NPM or Homebrew, but I was curious: with supply chain attacks and package malware becoming more prevalent (linked in comments), would creating an economic side of the package distribution help? I get NPM sells enterprise SaaS, but I was thinking on the client end.

For e.g.

Opt 1. Paid Homebrew / NPM CLI

A paid package manager that analyzes the downloaded binary or package upon install. Basically "anti virus" package manager?

Opt 2. Paid packages

Instead of open source software developers seeking funding through open collective what if they could allow you to pay 1.99 via homebrew or npm to buy a license to the package some how?

I get the philosophical wrinkles in this, just curious peoples thoughts.