3 ms·
Doesn't the responsibility for banning here lie with NPM? Who cares if this person can publish code to Github? The channel used to exploit trust was NPM, and I'
by giaour 4y ago
Doesn't the responsibility for banning here lie with NPM? Who cares if this person can publish code to Github? The channel used to exploit trust was NPM, and I'd much rather see someone who engaged in software supply chain sabotage get banned on artifact repositories than on a code hosting site.
- usrn 4y agoI don't think NPM is interested in taking responsibility. IMO at this point the responsible thing to do is just don't use npm.
- hulitu 4y agowhy not ? it is a very good way to test your backup. Aaa, you don't have any ? Bad luck / s
- VoidWhisperer 4y agoGithub is NPM's parent company at this point, so I guess they have similar policies for dealing with this sort of stuff at this point. My best guess is MSFT (which is the owner of both) is wary of taking a political stance here.
- giaour 4y agoI didn't realize that GH owned NPM. Still, I would expect policies on bans to be pretty different between the two given the different roles each org plays in the larger ecosystem. Microsoft has taken some fairly assertive political stances wrt Ukraine, so I'm not sure corporate neutrality is to blame here (take this with a grain of salt: I work for MSFT, albeit not on anything remotely related to policy or comms).
- unknownaccount 4y agoThey already took a political stance by letting him be unbanned. Theres no way this would ordinarily be allowed. But since the victims were only Russian and Belarusian people, Microsoft let the perpetrator get away with the crime. The message Microsoft is sending right now is loud and clear: That they dont take malware threats seriously. That it isnt a big deal when users upload malicious code / trigger a supply chain attack that permanently deletes peoples files. Because the worst thing that can happen is only a minor slap on the wrist.