4 ms·
Part of GitHub (I work at GitHub and lead the Packages team)
by clarkbw 7y ago
Part of GitHub (I work at GitHub and lead the Packages team)
- cmckn 7y agoHow does this acquisition relate to Package's support of npm artifacts? Or, I guess, how will Package's npm support change after this?
- clarkbw 7y agoThe post covers this. > Later this year, we will enable npm’s paying customers to move their private npm packages to GitHub Packages—allowing npm to exclusively focus on being a great public registry for JavaScript. Packages will continue to develop its npm registry. We have a lot of work to do in securing the software supply chain.
- mceachen 7y agoCan I be so bold as to suggest a new feature? It'd be wonderful, as a package consumer, to have visibility into some security metrics for a given package. This would be useful both at initial install time, and when the package is upgraded. Something like: 1) who are the latest commits GPG signed by? 2) is the package publisher using 2FA? 3) what is the security profile of all dependent packages? 4) are there any new authors (directly or via dependencies) since the last version (with links to the author and their contributions). These might help avoid prior situations where popular packages get injected with malware by new maintainers.
- clarkbw 7y agoYes, we (internally) call this a "Bill of Health" and believe that all packages should have this kind of diff-able information available. Understanding what's happening at the source level is key to being able to trust any package published.
- mceachen 7y agoNICE! It would be wonderful to expose that information! Somewhat related, I believe NPM pulled in (or co-opted) some of the heuristics from this: https://github.com/npms-io/npms-analyzer https://github.com/npms-io/npms-analyzer (but those don't seem to include any of the aspects I suggested above).
- csours 7y agoSlightly OT: Is Packages coming to Azure DevOps Server (local/corporate hosted)?