Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

To clarify things for the community:

1) No, they (Chinese developers) have not contributed more. You revoked access from @jbielick who was #2 contributor to the package behind you. He messaged me in Slack today that he received zero notification from you and simply received a notification from NPM that he was removed access from the package. You removed his access completely from NPM.

2) My email to you prefaced the concern of the China-based user with "completely unknown" and "To an outsider". Here's the original email to clarify it for people viewing this from an incorrect context:

    Hi Alex,

    Thanks for your work in the open source community.

    I am curious, since the project is open source, if you will be transparent as to the transfer of the koa-router repository and NPM ownership to a completely unknown user "ZijianHe" to the community.  Was there a monetary transaction?  Why did you choose him?  Why not transfer to the KOA org?

    To an outsider, this is all a huge red flag, as an unknown Chinese GitHub user suddenly has full control of a NPM package with 130K weekly downloads and is used by major corporations.
3) I did not "repeatedly" assert that. I stated the word "Chinese" one time. One time is not "repeatedly". I would share with the community your response to my message, but I am not going to do so.


I notice that Alex's claim about you "repeatedly" making accusation(s) regarding "Chinese" users seems to refer to your emails to NPM, not your email to Alex himself that you have provided above.

I hope my attempt to clarify this aspect doesn't take the focus off the other parts of your responses, because the issues you raise are concerning to me and I share your belief that the community deserves info about all this.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: