8 条评论

  • supriyo-biswas 8小时前
    Is any form of code analysis out of the question? Static and dynamic analysis of the code would seem like a promising idea rather than just trying to defer the update and hence the problem.
  • weinzierl 9小时前
    Seen favorably, staged publishing is a band aid. Seen more realistically I believe that in the long run it will even hurt our efforts for more secure infra.
    • buildfocus 8小时前
      How could it possibly hurt?

      For trusted publishing, it's not a band-aid, it's a significant improvement that kills an entire class of CI takeover publish attacks. I'm sure attackers will find another way but it's a big gap this is closing up.

  • madarco 8小时前
    meanwhile pnpm 10.x by default won't donwload packages younger than a day
    • stabbles 8小时前
      Is one day enough to find vulnerabilities? Who keeps an eye on new releases? Otherwise the problem continues to exist, just delayed by one day.
      • captn3m0 8小时前
        There’s almost a dozen cybersecurity companies scanning NPM publishes in real-time and analysing them.
    • jamietanna 7小时前
      *11.x
  • koinedad 14小时前
    Nice…maybe will help some of the recent attacks
    • turkeyboi 13小时前
      If maintainers actually use it
      • Klaster_1 13小时前
        This is the biggest question I also had after reading the blog post. Given the recent chain of attacks, wouldn't it make sense to enforce staged publish by default or at least gradually move over to it?
  • warmwaffles 1小时前
    Perfect, now we'll start seeing people automate auto publishing because they don't want to explicitly push a button to publish it.
  • bob1029 8小时前
    [dead]
  • eff-nix 11小时前
    [dead]
  • NicoHartmann 9小时前
    [dead]