Settings

Theme

Shai-Hulud and the risks of external dependencies

scotto.me

7 points by silcoon · 1 comment

Reader

1 thread
shomp

Or, npm can add trust ratings to packages and versions. And Github the parent company can lend a tiny fraction of resources and programmer power to developing static code analysis tools for npm packages.

This problem is completely solvable in two different ways:

1) everyone uses private feeds that use vetted versions only, and

2) Github/npm take responsibility for every package published to npm as the distributor.

Also the name Shai-hulud was chosen by the people who made the malware, you shouldn't dignify them by using the name they chose.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection