▲ | jimmyl02 3 days ago | ||||||||||||||||||||||||||||||||||
this being the 2nd large compromise of the week is not boding well from the NPM ecosystem... supply chain is and has been the new gold mine for bad actors it seems | |||||||||||||||||||||||||||||||||||
▲ | seanieb 3 days ago | parent | next [-] | ||||||||||||||||||||||||||||||||||
There have been practical suggestions that could prevent this but NPM has not yet adopted: - Prevent publishing new package versions for 24–48 hours after account credentials are changed. - Require support for security keys. | |||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||
▲ | lelanthran 3 days ago | parent | prev [-] | ||||||||||||||||||||||||||||||||||
> NPM has bigger problems - no adults in the room! For example, they've been rejecting signed packages since 2014 or thereabouts? Expect npm repos to be overflowing with AI-submitted crap that will lower the signal substantially due to not having any sort of identify via signing. |