| ▲ | Shai-Hulud and the risks of external dependencies(scotto.me) | |
| 6 points by silcoon a day ago | 1 comments | ||
| ▲ | shomp 6 hours ago | parent [-] | |
Or, npm can add trust ratings to packages and versions. And Github the parent company can lend a tiny fraction of resources and programmer power to developing static code analysis tools for npm packages. This problem is completely solvable in two different ways: 1) everyone uses private feeds that use vetted versions only, and 2) Github/npm take responsibility for every package published to npm as the distributor. Also the name Shai-hulud was chosen by the people who made the malware, you shouldn't dignify them by using the name they chose. | ||