4 ms·
The issue is that the dependency change will show up in the repo as: - "event-stream": "1.8.4" + "event-stream": "1.8.5" Looks completely innocuous, a patch
by atom_arranger 8y ago
The issue is that the dependency change will show up in the repo as:
- "event-stream": "1.8.4"
+ "event-stream": "1.8.5"
Looks completely innocuous, a patch version bump, but it can technically be a completely different package, it may not even have any relation to any open sourced code, people can push anything to npm.
People don't check in their dependencies. event-stream is hosted on npm and downloaded by people who download packages depending on it automatically. Given this situation there is no diff of it to view.
- mifreewil 8y agoyeah - thinking it'd be helpful for npm to have a diff command to check source changes when doing upgrades.
- btown 8y agoUnfortunately, this is made difficult to "bootstrap" due to npm not supporting/promoting repeatable builds - so you'd just see a diff of minified messes with no ability to track back to source code changes. You'd want to do this alongside a rollout of a larger ecosystem around cryptographically secure repeatable build tracking, which would take time and require "drag-along" of the entire ecosystem of abandoned packages.
- mifreewil 8y agoVery few packages actually contain minified sources - it's not really needed with modern build tools. I think it was an exception in this case, and that by itself could be suspicious. Current version of npm now contains a package-lock.json file which is made to make builds pretty close to deterministic. It contains the entire dependency tree of dependency names, versions, and hashes. I say pretty close because it's still possible to break "npm install" by unpublishing a package.
- balibebas 8y agoIf something looks innocuous a diligent engineer will review it twice as hard. I used to fail reviews on one-liners during my professional years with people around me asking me what's taking so long—it's just one line of code.
- atom_arranger 8y agoWell there's definitely a conflict between trying to get things done quickly and reviewing things thoroughly in most development jobs. You have to weigh the risk of going out of business because you didn't deliver value fast enough vs. the risk of having a security incident. In the Node ecosystem there are SAAS products (https://greenkeeper.io/ https://greenkeeper.io/) that will automatically update your dependencies, run your tests, and merge in the updates (that line change I showed is an example of what it would look like) if the tests pass. That shows you how much thought Node/JS developers put into upgrading their dependencies. The event-stream update would be done automatically in this instance because the code still worked, although it was compromised.