4 ms·
Can't there be a "package signature" of some sort that is specified and checked against in a package-lock.json or yarn.lock?
by technics256 6y ago
Can't there be a "package signature" of some sort that is specified and checked against in a package-lock.json or yarn.lock?
- dininski 6y agoI'll try to answer this from a JS-specific perspective. As someone previously mentioned - you do get hash checks if you're using `npm ci` in your CI/CD setup. You get the resolution path as well. Which is all you need to reproducibly resolve dependencies, *if* you have set up npm correctly in your pipeline. It would be unlikely to be exposed to this particular attack, at least not automatically in your deployment pipelines. However this is still very, very dangerous, because of day-to-day engineering, really. Any engineer doing a simple `npm install` can inadvertently bring in and execute malicious code from their machine. From there on out it would be somewhat trivial to gain further access to the same network the code war run from.
- fernandotakai 6y agopip has hashing signatures and i don't know why people don't use it. it's quite easy too. https://pip.pypa.io/en/stable/reference/pip_hash/ https://pip.pypa.io/en/stable/reference/pip_hash/ https://pip.pypa.io/en/stable/reference/pip_install/#hash-checking-mode https://pip.pypa.io/en/stable/reference/pip_install/#hash-ch...