@cadey "NPM has always been kinda weird compared to other open source package repositories, so them requiring something strange like that reads as reasonable." Ah that makes sense 🙃
Maybe we should establish more processes like banks do "we'll never ask this of you ever".
But then again, people also click on phishing links in emails saying "this is a phishing attack training, do not click on the following link:"
We should just stop using email honestly.