4 ms·
Depending on how important supply chain security is to your industry/company/team, validating the hash of every package is critical. If an attacker can manage a
by zivkan 3y ago
Depending on how important supply chain security is to your industry/company/team, validating the hash of every package is critical. If an attacker can manage an interception/man in the middle attack on your CI network, the hash check provides protection. If an attacker compromises the server you get packages from, having a hash provides protection as well. Automatically trusting the server's response to be correct, or automatically upgrading to newer versions (even if the package author strictly adheres to SemVer), puts you at risk at attacks similar to what we saw with SolarWinds around 2021.
- brabel 3y agoYour argument supports the idea of getting rid of the lock file and instead committing the hash in the original dependencies file - so that it's never an automatic process to update the hashes/versions.
- patmorgan23 3y agoZigs package manager takes this approach. https://zig.news/edyu/zig-package-manager-wtf-is-zon-558e https://zig.news/edyu/zig-package-manager-wtf-is-zon-558e