5 ms·
https://tanstack.com/blog/npm-supply-chain-compromise-postmortem https://tanstack.com/blog/npm-supply-chain-compromise-postmo... We (TanStack) just released ou
by crutchcorn 5mo ago
https://tanstack.com/blog/npm-supply-chain-compromise-postmortem https://tanstack.com/blog/npm-supply-chain-compromise-postmo...
We (TanStack) just released our postmortem about this.
- swyx 5mo agothank you for maintaining this inspiring ecosystem.
- dang 5mo ago(We changed the URL from https://github.com/TanStack/router/issues/7383 https://github.com/TanStack/router/issues/7383 to that above.)
- ____tom____ 5mo agoI didn't see a key section of a COE: "What are we doing to make sure this can't happen again?" Apologies if I missed it. There's some discussion of things under what could have gone better, but prevention is key, and the reports not done without it.
- crutchcorn 5mo agoWe had a few revisions of the postmortem with this included, but ultimately felt premature to include given how quickly we released this notice. That's not to say that we're not working hard on preventative work, however. We: - [x] Temporarily removed the cache from our PNPM setup - [x] Removed all caches from GitHub Actions - [x] Locked down all GitHub actions on the org to commit IDs instead of version numbers - [x] Enforced non-SMS GitHub 2FA (NPM & GitHub 2FA was already enforced, but SMS was previously allowed) - [x] Removed all usage of `pull_request_target` from our CI pipeline (already wasn't in our CD) - [ ] Are introducing `zizmor` as action linting to every repo via a PR check - [ ] Are likely introducing `CODEOWNERS` on `.github` folders to restrict merging to only the 7 core maintainers - [ ] Will replace the PNPM setup cache with `actions/cache/restore`, which has more secure defaults - [ ] Will replace the PNPM setup cache to be isolated between release and PR envs - [ ] May close the ability to make a TanStack PR as an external contributor (But we're absolutely not going closed source) We'll have a follow-up blog post that outlines all of this and how maintainers are able to secure themselves simiarly.