Replies: 3 comments 4 replies
-
|
yes |
Beta Was this translation helpful? Give feedback.
0 replies
-
|
Head to the npm support or feedback channels:
While GitHub owns npm, they operate as separate platforms with different support teams and policies. The npm registry API behavior you're describing is npm-specific and their support team would need to address it. |
Beta Was this translation helpful? Give feedback.
4 replies
-
|
registry APIs leak emails because they have maintainer account data in public JSON metadata. Intended for developer collaboration, this feature allows bots to get. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Select Topic Area
Question
Body
Recently I got some automated spam email that seems like it got sent to everyone who has published a package to npm. After investigating how they got my email despite not putting it in package.json or anywhere else visible through the npmjs web interface, I discovered that the npmjs registry leaks the email address of every user through the
maintainersfield in the api response. When creating my npmjs account it was not clear at all that the email address would be made public. Why is it made public? Can this be reconsidered? And if not can it please be made much more clear that your email address will be leaked?Beta Was this translation helpful? Give feedback.
All reactions