4 ms·
This is why I commit node_modules to my own repos.
by CodeWriter23 4y ago
This is why I commit node_modules to my own repos.
- 0des 4y agoUnless you are reviewing the code in your assumedly large bundle of dependencies there, this is not a solution if you weren't posting this in jest
- CodeWriter23 4y agoNot in jest. Still using node_modules from before these stunts started to occur. I recognize I am accepting risk. What I am avoiding is the surprise of a ^version-compatible file introducing new and unwanted “features”.
- pabs3 4y agoWhat do you do for security updates? There are a lot of them for NPM modules. Seems GitHub manages the database for those now: https://github.com/advisories https://github.com/advisories
- ficklepickle 4y agoI swear 99% of them are prototype pollution or regex DOS that don't apply to how I'm using the dependency.
- CodeWriter23 4y agoSnapshot VM, npm install
- pabs3 4y agoAnd how do you know that is safe and hasn't exfiltrated all your data or used a VM escape exploit.
- 0des 4y agoEven then, if undocumented functionality is waiting for a certain day or certain action for something to execute you have no way in asserting one way or the other if it is safe because you haven't reviewed it.