3 ms·
It is also the norm to strictly pin dependency versions in the npm-ecosystem, at the project-level, via lockfiles. So simply doing an `npm install` in an existi
by inbx0 4y ago
It is also the norm to strictly pin dependency versions in the npm-ecosystem, at the project-level, via lockfiles. So simply doing an `npm install` in an existing project won't install the new trojan.
Yes, versions aren't usually pinned at the package-level, so if you install a new dependency that introduces the trojan to the project, then yeah your are compromised. Not sure if that happens to "millions of servers" in a few weeks tho, it'd have to be a pretty popular package at least and remain undetected when these millions of developers presumably test the new code that their new dependencies introduce.
Having versions tightly pinned in the package-level isn't a free gift. It'll lead in lots of duplicated versions of a practically same package being installed and ran when two higher level dependencies have a transitive dependency to sligthly different (but in practice compatible) versions of the same package.
Edit: I agree with the points about sandboxing and permission configuration, etc, though. That's hopefully also coming to Node at some point.
- rubenfiszel 4y agoIt seems to me that the norm in the node world is to use ^ specifier to say anything that is non-breaking, and that `npm install` will not respect the package-lock.json, only `npm ci` does.
- hobofan 4y ago> and that `npm install` will not respect the package-lock.json I'm not sure where you get that from. Maybe this was the case for the first NPM version with package-lock.json, but at least for the current and previous LTS version, it is definitely being respected.
- rubenfiszel 4y agoThis is correct up to a point (which is why npm ci exist at all), I agree that in general since you would have to mutate the package.json for that to happen, my point is moot (https://stackoverflow.com/questions/45022048/why-does-npm-install-rewrite-package-lock-json https://stackoverflow.com/questions/45022048/why-does-npm-in...) but npm install will overwrite the package-lock.json if they do not match.