logoalt Hacker News

bearttoday at 3:07 AM1 replyview on HN

There is a time window - https://docs.npmjs.com/policies/unpublish


Replies

zarzavattoday at 3:15 AM

Yes but they didn't do it properly. They only allow unpublishing if there are no dependants, which means it can't be used to pull a package version for security reasons.

It should be that within the first X hours you can pull a version regardless of dependants, after that you should need approval.