3 ms·
Don't. Deploy. From. Internet.
by vitaliyf 9y ago
Don't. Deploy. From. Internet.
- StavrosK 9y agoWhat's the alternative? Have the maintainer snail-mail you the packages?
- vitaliyf 9y agoYou run a private NPM mirror where you copy dependencies that you rely on, after auditing them (for code quality and licensing).
- chris_7 9y agoI don't know JS, but this sounds like a lot more work than just checking everything into your repo?
- fareesh 9y agoRealistically if someone were to sneak something in, what kind of audit would you need to be able to catch it?
- weinzierl 9y agoThis, or if you have the money there are companies that do that for you.
- StavrosK 9y agoWouldn't just pinning the hash of a package be a better solution?
- tomjakubowski 9y agoThat’s probably fine from the security perspective, but the hash won’t make the package re-appear if it disappears out of nowhere. That’s the other benefit of a private/on-premesis mirror.
- eitland 9y agoYarn caches locally, doesn't it?
- StavrosK 9y agoTrue. I work with PyPI and it's been extremely solid for years, so we tend to just not consider this a problem at all. Pipenv stores hashes for each package version as well, so you get the security aspect built in. Pipenv has pretty much fixed Python packaging/dependencies, in my opinion. It's the all-in-one tool I've always wanted. If you do any Python work, try it, it's great.
- the_duke 9y agoEasiest solution without infrastructure imo is to vendor node_modules as a git submodule. (Of course it's even easier to just add node_modules to the repo but that is messy).
- aabbcc1241 9y agoand you better fork the git repo, otherwise the incident happening to npm can happen on github / whatever remote repo.
- perlgeek 9y agoHave a local mirror with the relevant packages, or a caching proxy.
- MarkyC4 9y agocreate a mirror registry containing the packages you depend on
- deleted 9y ago[deleted]
- astrobe_ 9y agoGit or similar?
- imsofuture 9y agoSeriously, you shouldn't depend on third party things existing happily to cut releases of your software. Mirror, vendor, proxy, whatever -- but absolutely you should strive to yourself be the biggest weakness in your dependency chain.