3 ms·
This is great! With some small automation for maintainers, we could help with the "Don't install anything that is less than 7/14/X days old" by just pinning de
by wesleytodd 8y ago
This is great! With some small automation for maintainers, we could help with the "Don't install anything that is less than 7/14/X days old" by just pinning dependencies and regularly publishing updates just for dependency tree updates.
For most projects the dep tree is small, and this level of maintenance is low. People always hate on me for saying it, but I think this level of effort would be worth it to protect the users of my modules.
- Klathmon 8y agoI actually think there is room here for an upgrade "helper" or wrapper (yeah I know, I'm gonna try to solve npm package problems by making a new npm package!) Something that can allow you to delay most updates by a set amount of time, only allow installing or updating dependencies based on a personal whitelist of contributors or authors (requiring some manual review perhaps of diffs from code that isn't from your approved contributors list), and a few other things. It won't stop everything, and a determined attacker will still get things through, but it could at least make it a bit harder.
- 21 8y agoIt doesn't scale. If a significant portion of the user-base starts doing this, what will happen is that security issues will be discovered 7/14/X days after they are introduced, not immediately. Because the fundamental problem is still there: nobody is reviewing the code.
- kevinsimper 8y agoYes, that would be a tool that would be very appreciated and I think even companies would like to adopt it. Changing maintainers behaviors can maybe be difficult, so starting from a normal user could maybe be easier?