4 ms·
Installing the budibase server from npm pulls in over a thousand transitive dependencies. The npm install command reports that there are 39 known vulnerabilitie
by segphault 5y ago
Installing the budibase server from npm pulls in over a thousand transitive dependencies. The npm install command reports that there are 39 known vulnerabilities in budibase's dependencies, including 9 that are classed "high" and 3 that are "critical" severity.
The dependency graph includes a lot of crap, like packages containing trivial single-line functions like "is-object" and "is-stream". That's a very large attack surface considering the poor security practices in the npm ecosystem[0] and the growing frequency of attacks on transitive dependencies[1].
I'm interested in hearing from the creators what steps they take to audit their transitive dependencies in order to prevent this application from being compromised. Given that a tool like this would typically be given privileged access to internal data sources, it seems like a tempting target. I don't think I'd be comfortable using this in production.
[0]: https://www.bleepingcomputer.com/news/security/52-percent-of-all-javascript-npm-packages-could-have-been-hacked-via-weak-credentials/ https://www.bleepingcomputer.com/news/security/52-percent-of... [1]: https://news.ycombinator.com/item?id=28962168 https://news.ycombinator.com/item?id=28962168
- FpUser 5y ago>"The dependency graph includes a lot of crap, like packages containing trivial single-line functions like "is-object" and "is-stream". I've never understood introducing this kind of dependencies. Depending on the legal conditions (usually favorable) one can simply extract the code they need from those packages and put it into some consolidated lib on their own.
- shogunpurple 5y agoHi, Thanks for the comment. We have just undergone a full security audit as of 2 weeks ago - any infrastructure or code vulnerabilities are currently being worked on. Many JavaScript projects contain huge dependency trees - it is unfortunately the nature of a 3rd party module-heavy ecosystem, and can be hard to tame the sheer size of the tree. We will update or pin dependencies as needed, to solve the security issues being reported by NPM. I should also mention that since budibase is self-hostable, it can be run inside all of your existing infrastructure and network - providing additional layers of security that you can control. Appreciate the feedback, and the information regarding transitive dependencies - interesting article. Note: Seems like source [0] has a broken link.
- deleted 5y ago[deleted]
- MisterSandman 5y agoYou're not wrong, but also, npm audit is pretty much a joke, and those "high" vulnerabilities aren't as bad as the terminal would want you to think. Should absolutely be fixed, but just relying on npm audit is a bit simplistic. Your critique about packages for is-object is valid, though.
- EMM_386 5y agoYou are giving far too much credence to npm audit and the severity of those warnings. What ones did you see that you think can "compromise" this JavaScript application? I'd be curious.
- rmbyrro 5y agoAs it becomes more difficult to sustain tech choices related to Javascript, I wonder if the web industry will start to slowly divest from it and embrace decent technologies using Wasm, or if we're past the point of no hope to free ourselves from JS...
- daertommy 5y agoNpm audit is a bit of a joke