kartykp/gat-bypass-2fa-docs
@reggi/path-to-regexp
dependabot/npm_and_yarn/main/copy-to-clipboard-4.0.2
dependabot/npm_and_yarn/main/eslint-10.4.0
dependabot/npm_and_yarn/main/npmcli/eslint-config-7.0.0
dependabot/npm_and_yarn/main/proc-log-7.0.0
dependabot/npm_and_yarn/npm_and_yarn-826852524d
dependabot/npm_and_yarn/npm_and_yarn-ab9a7f4bc2
deprecate-totp-2fa
dhei/classic-tokens
gat-bypass-2fa-docs
jpg619/fix-accessibility-content-flow
jpg619/version-bump-tar-2
kartykp/gat-bypass-2fa-docs
kartykp/upgrade-path-to-regex
main
maitxn/version-bump-tar
patch-1
reggi/cache-based-on-version
reggi/dev-engines
reggi/fix-transform-prettier
reggi/overrides
update-search-sensitivity
| 1 | --- |
| 2 | title: Dispute Resolution |
| 3 | edit_on_github: false |
| 4 | --- |
| 5 | |
| 6 | This document describes the steps that you should take to resolve naming disputes with other npm publishers. It also describes the steps you should take if you think a name [infringes your trademark](#trademarks). |
| 7 | |
| 8 | This document is additive to the guidelines in the [npm Code of Conduct][conduct] and [npm Open-Source terms][open-source-terms]. Nothing in this document should be interpreted to contradict any aspect of the npm Code of Conduct or Open-Source Terms. |
| 9 | |
| 10 | ## tl;dr |
| 11 | |
| 12 | 1. Open a support ticket at [https://support.github.com/contact/npm-name-disputes](https://support.github.com/contact/npm-name-disputes). |
| 13 | 1. Fill out the form with as much detail as possible. |
| 14 | 1. Support will address your request. Please note submitting a report does not guarantee the transfer of a package, org, or username. |
| 15 | |
| 16 | ## When to use this process |
| 17 | |
| 18 | This process is an excellent way to: |
| 19 | |
| 20 | - Request a name that you believe is currently misleading or could be confused with a name used by your company or open source project |
| 21 | - Request a name related to your company or open source project that cannot be claimed via account recovery |
| 22 | |
| 23 | This process does not apply if the package violates our [Terms of Use][open-source-terms], in particular our [Acceptable Use][acceptable-use] and [Acceptable Content][acceptable-content] rules, or our [Code of Conduct][conduct]. Those documents refer to this one to resolve cases of "squatting"; see below. |
| 24 | |
| 25 | If you see bad behavior or content you believe is unacceptable, refer to the Code of Conduct for guidelines on [reporting violations][violations]. **You are never expected to resolve abusive behavior on your own.** **We are here to help.** |
| 26 | |
| 27 | ## When not to use this process |
| 28 | |
| 29 | This process is not available for dispute requests due to lack of activity related to a specific name. |
| 30 | |
| 31 | Please also note there are cases where a party may have claim to a specific name, but giving that name to the requesting party would pose a supply-chain risk to the npm ecosystem. In such cases, requests may be denied independent of the validity of the claim. |
| 32 | |
| 33 | ## Trademarks |
| 34 | |
| 35 | npm processes Trademark claims under GitHub's [Trademark Policy](https://docs.github.com/site-policy/content-removal-policies/github-trademark-policy). |
| 36 | |
| 37 | If you think another npm publisher is infringing your trademark, such as by using a confusingly similar package, org, or user account name, please submit a Trademark Policy Violation Report via our [form](https://support.github.com/contact/trademark-policy). |
| 38 | |
| 39 | Use of npm's own trademarks is covered by our [Logo and Usage Policy][logos-and-usage]. |
| 40 | |
| 41 | ## Changes |
| 42 | |
| 43 | This is a living document and may be updated from time to time. Please refer to the [git history for this document](https://github.com/npm/documentation/blob/main/content/policies/disputes.mdx) to view the changes. |
| 44 | |
| 45 | ## Definitions |
| 46 | |
| 47 | ### Squatting |
| 48 | |
| 49 | It is against npm's [Terms of Use][acceptable-content] to publish a package, register a user name or an organization name simply for the purposes of reserving it for future use. |
| 50 | |
| 51 | We do not pro-actively scan the registry for squatted packages, so the fact that a name is in use does not mean we consider it valid. The standards for what we consider squatting depend on what is being squatted: |
| 52 | |
| 53 | #### Packages |
| 54 | |
| 55 | Package names are considered squatted if the package has no genuine function. |
| 56 | |
| 57 | #### Organizations |
| 58 | |
| 59 | Organization names are considered squatted if there are no packages published within a reasonable time. If an organization is a paid organization, it may have private packages that are invisible to third parties. For privacy reasons, we cannot reveal whether or not an organization has private packages, so a paid organization will never be considered squatted. |
| 60 | |
| 61 | #### User names |
| 62 | |
| 63 | We are extremely unlikely to transfer control of a user name, as it is totally valid to be an npm user and never publish any packages: for instance, you might be part of an organization or need read-only access to private packages. |
| 64 | |
| 65 | ## License |
| 66 | |
| 67 | Copyright (C) npm, Inc., All rights reserved |
| 68 | |
| 69 | This document may be reused under a [Creative Commons Attribution-ShareAlike License](https://creativecommons.org/licenses/by-sa/4.0/). |
| 70 | |
| 71 | [conduct]: /policies/conduct |
| 72 | [open-source-terms]: /policies/open-source-terms |
| 73 | [acceptable-use]: /policies/open-source-terms#acceptable-use |
| 74 | [acceptable-content]: /policies/open-source-terms#acceptable-content |
| 75 | [violations]: /policies/conduct#reporting-violations-of-this-code-of-conduct |
| 76 | [logos-and-usage]: /policies/logos-and-usage |