3 ms·
Mitigate? Stop using random packages. Prevent? Stop using NPM and similar package ecosystems altogether.
by HighGoldstein 10mo ago
Mitigate? Stop using random packages. Prevent? Stop using NPM and similar package ecosystems altogether.
- metaltyphoon 10mo ago> and similar package ecosystems altogether Realistically, this is impossible.
- baq 10mo agoat some point having LLMs spit out libraries for you might be safer than actually downloading them.
- Eduard 10mo agoLLMs will happily copy-paste malware or add them as dependencies
- morshu9001 10mo agoThis does help. Even before, I was pretty careful about what I used, not just for security but also simplicity. Nowadays it's even easier to LLM-generate utils that one might've installed a dep for in the past.
- Muromec 10mo agothis kicks the can down the road until we get supply chain attacks through LLM poisoning, like we already do with propaganda
- christophilus 10mo agoWell, he didn’t say vibe code. Presumably, you’d still be reviewing the AI code before committing it. I ran a little experiment recently, and it does take longer than just pulling in npm dependencies, but not that much longer for my particular project: logging, routing, rpc layer with end-to-end static types, database migrations, and so on. It took me a week to build a realistic, albeit simple app with only a few dependencies (Preact and Zod) running on Bun.
- pixl97 10mo agoHeh, that's if the reviewer actually is a human doing their job and not another AI just waiting for the right keyword to act like a manchurian candidate.
- throw-12-16 10mo agoor just vendor your deps like we have been doing for decades.
- baq 10mo agostill need to read them to make sure you don't vendor a trojan in the first place.
- throw-12-16 10mo agoauditing is the first step in vendoring a dep by my definition of the practice
- array_key_first 10mo agoIt's really, really not. Just write the libraries yourself. Have a team or two who does that stuff. And, if you do need a lib because it's too much work, like maybe you have to parse some obscure language, just vendor the package. Read it, test it, make sure it works, and then pin the version. Realistically, you should only have a few dozens packages like this.
- anthk 10mo agoDoes this happen with CPAN? At least they seemed to have policies: https://security.metacpan.org/ https://security.metacpan.org/
- cromka 10mo agoThat package wasn't any more random than any other NodeJS package. NPM isn't inherently different from, say, Debian repositories, except the latter have oversight and stewardship and scrutiny. That's what's needed and I am seriously surprised NPM is trusted like it is. And I am seriously surprised developers aren't afraid of being sued for shipping malware to people.
- bigfatkitten 10mo ago> NPM isn't inherently different from, say, Debian repositories, except the latter have oversight and stewardship and scrutiny. Which when compared to NPM, which has no meaningful controls of any sort, is an enormous difference.
- throw-12-16 10mo ago"NPM isn't inherently different from, say, Debian repositories, except the latter have oversight and stewardship and scrutiny" Yeah thats the entire point.