5 ms·
Will this be met with a shrug from the JS community? Or is this the come to Jesus moment for the JS supply chain?
by dodgerdan 4y ago
Will this be met with a shrug from the JS community? Or is this the come to Jesus moment for the JS supply chain?
- rmbyrro 4y agoWas this incident facilitated by something inherent in the JS ecosystem? I have the impression it wasn't. The JS ecosystem sucks, but anyway, not particularly their fault in this case.
- VoidWhisperer 4y agoFor once, I don't think this highlights an issue exclusively specific to JS.. this could've happened to any package system that Github owned when the attacker was able to pivot after accessing the private repos.
- tuxie_ 4y agoWhat would you expect the JS community do after this? What would you do?
- stolenmerch 4y agoAs a member of the JS community: shrug. I revoked my OAuth apps on Github, changed my passwords. The tarballs are unaffected. Not worried.
- throwaway290 4y agoI hope this is self-deprecating humor, but for anyone that takes it at face value: The implication of a successful attack on NPM, with huge unvetted dependency graphs currently in fashion, would be that any of the thousands dependencies of a modern small JavaScript app could suddenly include malicious code that runs your dev machine or your production systems. (That's why the key part of the announcement is "GitHub is currently confident that the actor did not modify any published packages in the registry or publish any new versions to existing packages".)
- ratww 4y agoWhat do you expect the community to do? Stop using thousands of packages? Start vetting packages, as if security was important? There are already dozens of us saying it is possible to not have too many dependencies, and vet packages before installing. But every time we open our mouths we are treated as if we just escaped some sort of insane asylum. At a place I worked in the past we used to have a 40-line microservice using plain-node without any dependencies. That was by design. One junior dev took it upon himself, in their spare time, to convert the whole thing to use some js MVC framework, complete with a full-blown build process, transpilers, and all the nine yards. There was a big discussion in the PR and a lot of juniors complained that we should migrate because they "didn't learn plain node.js in college". We can't have nice things anymore.
- dodgerdan 4y ago> What do you expect the community to do? Ensuring that the core infrastructure of their software systems doesn’t have the same security standards as teenagers wordpress site would be an awesome start.
- ratww 4y agoDepending on what you're calling core infrastructure, it might not be something under control of "the community".
- dgb23 4y agoIt surprises me that colleges teach web frameworks.
- SkyPuncher 4y agoYes, because this fundamentally wasn't an attack against NPM or any specific package manager. This stemmed from a breach at Heroku.
- dotancohen 4y ago> Will this be met with a shrug from the JS community? Go read the comment that begins "Top 10 maintainer here". Not even a shrug.
- EnKopVand 4y agoI’m of a bit of an opposite mind on the many, and usually very public, NPM security issues. Because from my experience the JS ecosystem, and it’s woes, teach a lot of people to never trust the part of their operation that is coming from someone else. I mean not everyone, obviously, but in my anecdotal experience it’s far more common to see good package control and review processes for JS than any other language, well except for maybe Python when the Python is done by software engineers and not “data-scientists”. Supply chain security is immensely important, and I encourage you not to learn about it the hard way like I did. Which somewhat ironically happened in the .Net ecosystem when one of our trusted Nuget packages got hacked many years ago. Now, I could be mistaken and I hope I am, but I suspect that if you ask a Java, a JS and a C# developer if they trust their ecosystem, then only one of them is likely to say yes. So no, there won’t be some great revelation in the JS community. The best you can hope for with stories like these is that fewer developers feel like imposters when they realise that GitHub stores plaintext security assets in their logs.