4 ms·
A valid point, but from my view there are two scenarios: 1. You have a known security bug in one of your dependencies that is discovered. If it is a serious b
by Mr_Yolokovich 5y ago
A valid point, but from my view there are two scenarios:
1. You have a known security bug in one of your dependencies that is discovered.
If it is a serious bug you need to check if you are affected and make sure to use the right version and remove the faulty version from your registries. In this case any private npm registry will happily allow you to manually upload the correct version.
If your "security" is that you rely on your dependencies to be automatically updated when you happen to rebuild your product then sure this will increase your exposure time.
If it is not serious then it does not matter.
2. Somebody has uploaded something malicious (with some very high profile cases of late)
Then this might save you. Given that the community finds the malicious code before your delay period runs out.
- taubek 5y agoYeah, it all comes down to workflow and standard operating procedures.
- daudmalik06 5y agoTotally agree with you, i think it's time to think carefully and immediately start using services like Vulert(https://bit.ly/336DZub https://bit.ly/336DZub) that tracks your open-source softwares for free and notifies you in real-time if any seccurity issue is found within your applciation. it's free. atleast in this way we can secure ourselves from supply chain attacks