You're referring to a link buried within 'Legal Stuff' at the bottom of the page, away from all other actionable sections linked to a package.
I don't think that's even close to being a satisfactory call-to-action.
Whenever I've picked a name for a project, I've always generated them by combining words together with hyphens. If I realised that I could take over package names that were being squatted, there are many times I would have done so.
Yes? I mean the one clearly labeled "Package Name Disputes"... it's not like this page needs a big CTA, it's something you'd reasonably expect to find within a "Policy" or "Terms of Service" page but instead it has a link on every footer.
And actually... "Package name disputes" are mentioned in different ways within 5 of the 6 links in the "Legal stuff" section, so I am pretty sure that it's just for lack of reading/searching, not because they are actively trying to hide it.
If a package has only one published version with no dependents or real users, the call-to-action should be a button near the top of the screen that should describe the action expected (e.g. "claim package name").
Clicking on this button should start a partly-automated, formal process and not require writing an email or manually soliciting contact with the original owner. This process can then be managed by NPM, who can stop relying on hearsay over whether these disputes are being resolved.
The only reason to bury this within the 'Legal Stuff' section is when you erroneously assume that this action is likely to be a legal issue and informed by patent, trademark or copyright law.
The current solution is cumbersome, not pointed to sufficiently, and likely to become progressively worse as the NPM ecosystem expands. I'd bet many NPM users aren't familiar with this resolution process. (Apart from those that remember the kik and left-pad debacles. "hahah, you’re actually being a dick. so, fuck you. don’t e-mail me back.")
All I'm saying is that this process needs to be clear, structured and measurable.
If NPM was doing a good job here, this HN post would never have been upvoted.
I agree with that, it could be improved and automatically detect abusers.
NPM is also improving, AFAIK they were really messy in the beginning and now getting better and better. This issue came up as I mentioned in other places because of an initial error that has been corrected long ago (case-sensitive package names). So hopefully someone will see your comment and do something about it.
I don't think that's even close to being a satisfactory call-to-action.
Whenever I've picked a name for a project, I've always generated them by combining words together with hyphens. If I realised that I could take over package names that were being squatted, there are many times I would have done so.