5 ms·
It's just a mirror service address, the NPM package is the same. Worrying too much about cybersecurity is a bit of a storm in a teacup.
by lqs469 7y ago
It's just a mirror service address, the NPM package is the same. Worrying too much about cybersecurity is a bit of a storm in a teacup.
- warpech 7y agoWell, how do you know it's "just" a mirror service, and it is not using a zero-day to exploit your system, by installing a root-kit or copying your code to their servers? I agree that it's a valid concern.
- lqs469 7y agoIn fact, you can compare the installed dependencies code line by line, Javascript won't be compiled anyway.
- gpmcadam 7y agoIf you're concerned about injection into a third-party package, you should be using `package-lock.json` (or equiv) and integrity hashing your dependencies at install time.
- wp381640 7y agosigned packages would go some way towards better distributing npm
- yellow_lead 7y agoI'll admit I don't know the specifics of how NPM works or if it's even a valid concern. But cybersecurity is becoming much more about a power grab than actual hacking these days. And if you depend on things in China for your American company, you can bet that will be on the table for any future attacks.