4 ms·
Not in jest. Still using node_modules from before these stunts started to occur. I recognize I am accepting risk. What I am avoiding is the surprise of a ^versi
by CodeWriter23 4y ago
Not in jest. Still using node_modules from before these stunts started to occur. I recognize I am accepting risk. What I am avoiding is the surprise of a ^version-compatible file introducing new and unwanted “features”.
- pabs3 4y agoWhat do you do for security updates? There are a lot of them for NPM modules. Seems GitHub manages the database for those now: https://github.com/advisories https://github.com/advisories
- ficklepickle 4y agoI swear 99% of them are prototype pollution or regex DOS that don't apply to how I'm using the dependency.
- CodeWriter23 4y agoSnapshot VM, npm install
- pabs3 4y agoAnd how do you know that is safe and hasn't exfiltrated all your data or used a VM escape exploit.
- 0des 4y agoEven then, if undocumented functionality is waiting for a certain day or certain action for something to execute you have no way in asserting one way or the other if it is safe because you haven't reviewed it.