Skip to content

What's on version 3.3.3333? #30032

Description

My apologies if this is not the right issue type. I just think that needs urgent attention as it could mean npm is compromised (which is not unheard of).

I got this from my project.

screen shot 2019-02-22 at 10 53 14 am

Surprised, I went to the npm page for typescript and got this.

screen shot 2019-02-22 at 10 52 25 am

Is this expected?

Activity

  1. tkausl commented on Feb 22, 2019

    @tkausl
  2. RyanCavanaugh commented on Feb 22, 2019

    @RyanCavanaugh
    Member

    We published 3.3.3333 because, unfortunately, npm rejected our PR to allow versions with an infinite number of repeating digits.

  3. dashmug commented on Feb 22, 2019

    @dashmug
    Author

    Thank you for the response. It is expected then. I'll close this.

  4. fictitious commented on Feb 22, 2019

    @fictitious

    Ryan Cavanaugh (@RyanCavanaugh) you'd have better chances with npm if you went with PR allowing such versions to be published on GitHub first

  5. RyanCavanaugh commented on Feb 22, 2019

    @RyanCavanaugh
    Member

    We had an offline conversation, but couldn't come to an agreement about whether 4.9999... should be equivalent to 5.0 or not.

  6. jacobwgillespie commented on Feb 22, 2019

    @jacobwgillespie

    Sorry if I'm just missing a joke here, but I'm probably not the only one still confused. 🙃

    Given that automated tools like Greenkeeper/Dependabot etc are now recommending upgrading from 3.3.3 to 3.3.3333, is this new version legit? We're trying to audit this from a security perspective, and this kind of release is unusual behavior for semver, etc. Also I think this version probably blocks any automated upgrades to 3.3.4 since 4 is less than 3333.

    Besides this issue, I can't find anything relating to what this is or why it was published, and there are actual code changes in the diff between the the 3.3.3 and 3.3.3333 versions.

  7. DanielRosenwasser commented on Feb 22, 2019

    @DanielRosenwasser
    Member

    Sorry, humor aside, the new version is legit.

  8. jacobwgillespie commented on Feb 22, 2019

    @jacobwgillespie

    Does that mean there will be no version >=3.3.4 <3.3.3333?

  9. RyanCavanaugh commented on Feb 22, 2019

    @RyanCavanaugh
    Member

    Correct. Any future version on the 3.3 line will be something like 3.3.4000

  10. weswigham commented on Feb 22, 2019

    @weswigham
    Member

    Or more likely 3.3.33333 given what we've already done tbh.

  11. Jessidhia commented on Feb 22, 2019

    @Jessidhia

    Missed an opportunity to have 3.1.4159 🤔

  12. alexeagle commented on Feb 22, 2019

    @alexeagle
    Contributor

    I know you guys don't believe in semver but now you have to introduce floating point errors into it? I feel like this change is just 1/3 whimsical.

  13. zaoqi commented on Feb 23, 2019

    @zaoqi

    qiaodaima

    thinking

    讓我想起了Microsoft Windows版本號,雖然我現在不用Microsoft Windows,也不用wine,同時也在試圖刪除GNU和Linux和BSD(指我可能將實現一個運行於ARM,Intel芯片之上的整個內核作為一個我設計的編程語言解釋器所以不一定需要MMU的內核及操作系統)。

  14. chase-moskal commented on Feb 24, 2019

    @chase-moskal

    Jessica Franco (@Jessidhia)

    Missed an opportunity to have 3.1.4159

    we can still have hope for typescript@3.14.1592

  15. we11adam commented on Mar 1, 2019

    @we11adam

    This version number is in no way a joke I can appreciate because I literally spent a few minutes reading this issue and 2c02f13 trying to figure it out only to find out it's really meaningless.

    Can we stop this from happening again, please? Thanks! Daniel Rosenwasser (@DanielRosenwasser)

  16. TheReincarnator commented on Mar 3, 2019

    @TheReincarnator

    Not very professional, misleading, irritating. And not consistent in terms of semver. This is why people outside the JS/TS community are taking it not serious.

  17. jkoepcke commented on Mar 11, 2019

    @jkoepcke

    I would really like to know how many developer hours have been wasted worldwide investigating about this version number... with great power comes great responsibility :)

  18. KissBalazs commented on Mar 11, 2019

    @KissBalazs

    Nice to see that other professionals still use their highschool homework versioning systems as well.

  19. sysmat commented on Mar 14, 2019

    @sysmat

    Probably in semantic versioning is legit, but it is strange

  20. forresthopkinsa commented on Sep 23, 2019

    @forresthopkinsa

    So many complainers. I came across this issue because I saw the joke in my NPM logs and I wanted to know where to direct my appreciation. Made me chuckle. We don't need to be so serious all the time.

  21. locked as resolved and limited conversation to collaborators on Oct 21, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Working as IntendedThe behavior described is the intended behavior; this is not a bug

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions