3 ms·
There is no way for npm to guarantee security, other than auditing each version from each package one by one. Then, what is secure for one user may not be secur
by partycoder 8y ago
There is no way for npm to guarantee security, other than auditing each version from each package one by one. Then, what is secure for one user may not be secure enough for other.
So it is misleading to say it is secure and that security is built in.
- elmigranto 8y agoMost likely only popular packages, forget about making `npm publish` a free security review (unless it runs custom eslint rules for stuff like Regex backtracking, etc.). And probably only guarantee it for particular version. And "guarantee" is probably too strong a word for it, unless there is a contract with some kind of liability attached. Same for "security", from the wording of it, they promise notifying about vulnerabilities, not performing comprehensive audits.
- elmigranto 8y ago> So it is misleading to say it is secure and that security is built in. Well, it is a PR blogpost with literally that goal of wording most basic and boring things in a way that sounds maximally sensational and groundbreaking without becoming a lie. Example: see how they comment on performance improvement. Instead of "compared to previous major relase, npm 5" it says "compared to 1 year ago".
- partycoder 8y agoYeah, hopefully now they don't have a progress bar that consumes most of the running time :)