Thoughts on Allowing Crates with the Same Name


I think the best we could do (this has also been discussed before, I just couldn't find the thread), is to have a field in the manifest that would allow you to specify which other packages yours is similar to. Then, when installing either package, a note would show up listing some similar packages.

This, in and of itself, could be used by spammer crates to inject their crate into the similar list of popular crates. The way I'd mitigate that is to have the list sorted by a "trust metric" (computed from popularity, maintaining account, etc.) and only crates with a good enough trust metric show up in the similar list at all.