Dealing with npm hack!!! #181193
Replies: 3 comments
-
|
Yeah, supply chain attacks are scary stuff, you're basically trusting thousands of strangers every time you run Practical defenses:
Alternatives to npm itself:
Going full paranoid mode: Honestly though? You can't eliminate the risk entirely. The JS ecosystem traded security for velocity a long time ago. Just be thoughtful about what you add, keep dependencies updated, and don't install packages at 2am without checking what they do. |
Beta Was this translation helpful? Give feedback.
-
|
Totally get the paranoia. The supply chain has turned into the Wild West lately. Regarding the ecosystem chaos (and the "Sha1-hulud" reference—assuming you mean the concept of massive worm-like vulnerabilities), you don't need to ditch npm entirely, but you absolutely need to stop trusting it blindly.
|
Beta Was this translation helpful? Give feedback.
-
|
Noted!!!! Thank you soo much fellas! Quite a useful bunch of steps to keep in mind. This really does show it ain't about the code but also how one deals with Supply Chain stuff |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Select Topic Area
Question
Body
What's the general protocol to deal with npm hacks, like the Sha1-hulud and 2.0? Must be pretty nerve-wrecking to install any new packages for both personal and corporate projects?
If there's an alternate way to build projects without npm, I'm all ears :))
Beta Was this translation helpful? Give feedback.
All reactions