DEV Community

Discussion on: Day 5-6: Who downloads my unfinished npm package?!

Collapse
 
jnv profile image
Jan Vlnas • Edited

Congrats on the first published package!

Those downloads are very unlikely to be real users, like Vincent suggests, those are likely mirrors precaching the packages. There's also a huge monitoring infrastructure around supply chain security, companies like Snyk monitor new and updated packages for possible malware, so that's probably the reason for those downloads. You will likely see the traffic dropping off in the coming days.

Collapse
 
dagnelies profile image
Arnaud Dagnelies

Thanks. Yeah, it's probably because of bots... Lots of bots apparently... Another thought I had was CDNs copying it. Who knows. I'm curious to see how it will evolve ^^