4 ms·
> Both versions were published using the compromised npm credentials of a lead axios maintainer, bypassing the project's normal GitHub Actions CI/CD pipeline.
by koolba 6mo ago
> Both versions were published using the compromised npm credentials of a lead axios maintainer, bypassing the project's normal GitHub Actions CI/CD pipeline.
Doesn’t npm mandate 2FA as of some time last year? How was that bypassed?
- bakugo 6mo agoApparently it's possible to create access tokens that bypass 2FA. Might've been this. https://docs.npmjs.com/creating-and-viewing-access-tokens https://docs.npmjs.com/creating-and-viewing-access-tokens
- stingraycharles 6mo agoCorrect, for CI/CD systems that want to push releases.
- masklinn 6mo agoIf GitHub, gitlab, or circleci, trusted publishing is available. No access token whatsoever.