DEV Community

Discussion on: How I exploited NPM downloads... and why you shouldn't trust them

Collapse
 
bnb profile image
Tierney Cyren

While I've no doubt that NPM could create a popularity metric that aggregates a number of different attributes of a package (npms.io has already done it)

AFAIK the popularity metric that npm uses is from npms.io 😅

Collapse
 
andyrichardsonn profile image
Andy Richardson • Edited

Do you have a source for this?

Looking at the package on npms.io it has a much lower popularity rating (3% compared to 14% on NPM).

Edit: just to clarify, I also had this assumption but assumed I was misremembering after seeing the difference.

Collapse
 
bnb profile image
Tierney Cyren

The source I have is that I worked at a competitor when that change happened and was friends with folks at npm at the time. You're correct that there's apparently now deviation, and I'm not sure what that is - if npm continued using the original scoring and npms moved on, if npm moved on, or something else.