4 ms·
One thing I'm a bit confused about -- The attack was present in the minified JS, but not the source JS. (I'm ignorant about NPM.) Does this mean on NPM, the
by 2bitencryption 8y ago
One thing I'm a bit confused about --
The attack was present in the minified JS, but not the source JS.
(I'm ignorant about NPM.) Does this mean on NPM, the publisher gets to publish the source AND the minified version? Is there no validation that the minified code is sourced from the true source code?
- cnorthwood 8y agoThat's right, what gets published is published from a dev's machine (or perhaps CI), which can (and often does!) include files (perhaps build artifacts) which aren't committed to source control. Similar to how perhaps a Java package might have the source in source control, but you push a built JAR to your package manager.
- johncoltrane 8y agoPublishing a package on npm is not much more than uploading a .tgz. You could put _anything_ in it as long as it has a package.json at its root. Nothing is done on Npm's side to ensure things are what they claim they are upon publishing: they only check (superficially) if you are not by any chance trying to republish the latest version. Even that is done locally, not at the registry level.