| ▲ | ozim 5 hours ago | |||||||||||||
Ok big problem is lots of stuff installed for campaigns wasn't flagged in any feed. If maintainer access is taken over you still don't have any feed info, maybe it will be a bit faster to publish so if maintainer finds out.Everyone is looking at NPM how bad it is or AUR lately. Those are "free for all anything can happen, any kid can publish" repositories and that's what you get. No one looks at Debian and is saying "well maybe we should do what they do"... | ||||||||||||||
| ▲ | asdfaoeu an hour ago | parent | next [-] | |||||||||||||
> No one looks at Debian and is saying "well maybe we should do what they do"... Arch does exactly what Debian for the official repos. It was only the AUR that was compromised. Possibly the issue is that Arch is a bit to strict for the official repos which has forced too many people on to the AUR ones. | ||||||||||||||
| ▲ | maxbond an hour ago | parent | prev | next [-] | |||||||||||||
NPM has at least had the good sense to use namespaces so that it isn't entirely a free for all and is less of a high stakes game of Mavis Beacon. (You could typosquat a namespace too, of course.) Unlike AUR but also pip, cargo, etc. | ||||||||||||||
| ▲ | captn3m0 4 hours ago | parent | prev | next [-] | |||||||||||||
Author here - people are definitely looking at other places. This just happens to be where the attacks are, and gets disproportionate attention as a result. Do you have examples of campaigns that weren’t flagged? Everything except xz had a 1 day window and Dependency Cooldowns are super effective against most campaigns for that reason. See papers at https://kokkonisd.github.io/ for eg. | ||||||||||||||
| ||||||||||||||
| ▲ | PunchyHamster 3 hours ago | parent | prev [-] | |||||||||||||
> No one looks at Debian and is saying "well maybe we should do what they do"... You mean that having mature community with maintainers checking subscriptions and a "testing" channel where stuff only lands after few weeks of no problems is useful ? Who could possibly imagine!? Industry's gonna NIH > Ok big problem is lots of stuff installed for campaigns wasn't flagged in any feed. If maintainer access is taken over you still don't have any feed info, maybe it will be a bit faster to publish so if maintainer finds out. Technically at the very least company could throw their feed to AI and at least get some automated screening on the changes between versions | ||||||||||||||
| ||||||||||||||