this post was submitted on 03 Feb 2026
37 points (97.4% liked)

Free and Open Source Software

21501 readers
56 users here now

If it's free and open source and it's also software, it can be discussed here. Subcommunity of Technology.


This community's icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

founded 3 years ago
MODERATORS
top 7 comments
sorted by: hot top controversial new old
[–] ftbd@feddit.org 12 points 1 day ago (1 children)

Why should the update procedure for an application be handled by the application itself rather than a package manager? Let app devs focus on their app and repository maintainers on update manifests.

[–] IrritableOcelot@beehaw.org 7 points 21 hours ago (1 children)

Well, in this case I think it's a remnant of n++ predating any package manager on windows. I do think that an embedded self-updater is better than having to download a new version through the browser.

It wasn't entirely clear to me if the compromise effects those of us who installed it though scoop/winget, as the package manager should pull directly from the correct source, so the compromised updater shouldnt matter. Reinstalled to be sure.

[–] BartyDeCanter 1 points 16 hours ago (1 children)

This is it exactly. When I was using Npp, Windows didn’t have anything resembling a package manager. Does it even really have one now?

[–] IrritableOcelot@beehaw.org 4 points 15 hours ago (1 children)

I mean kinda. You have to use both WinGet and Scoop to cover all the use cases...

[–] TehPers@beehaw.org 2 points 15 hours ago (1 children)

There's also Chocolatey but I don't know if that gets used anymore.

When I first installed N++, none of these were a thing yet though. It was just the MSI installer.

[–] IrritableOcelot@beehaw.org 2 points 13 hours ago

I would say chocolatey and scoop are pretty much interchangeable. I don't remember why I landed on scoop. Agreed that until recently there have been no package managers on Windows whatsoever.

[–] BartyDeCanter 7 points 1 day ago* (last edited 1 day ago)

Fuck. I haven’t used Npp in a long time, but that’s awful. Glad they were able to get it fixed and their transparency is to be highly commended. But damn does it make me worry about other projects. Npp isn’t exactly obscure, but it’s also not exactly a massive target either.