You Think npm Is Just a Repository. It’s Actually a Battlefield.
Modern software registries are no longer neutral infrastructure; they are critical trust intermediaries. As supply chain attacks threaten the ecosystem, a dangerous tug-of-war exists between community-driven openness and authoritative security control. The real battle isn’t about safetyβit’s about who gets the power to define what code is ‘acceptable’.