Our company uses yarn 4 which has an option to prevent you from installing an npm package for the first number of days of its release. Most of these seem to be caught within that timeframe (1-3 days). https://gist.github.com/mcollina/b294a6c39ee700d24073c0e5a4e...
What happens when everyone adopts this policy? You just change it to two weeks?
Malicious npm packages detected across Red Hat Cloud Services
11–20 of 494 posts
Re: Malicious npm packages detected across Red Hat Cloud Services
#12Re: Malicious npm packages detected across Red Hat Cloud Services
#13'No Way to Prevent This,' Says Only package manager Where This Regularly Happens Edit: some people don't understand that it's a defence to https://en.wikipedia.org/wiki/%27No_Way_to_Prevent_This,%27_...
Re: Malicious npm packages detected across Red Hat Cloud Services
#14Re: Malicious npm packages detected across Red Hat Cloud Services
#15Our company uses yarn 4 which has an option to prevent you from installing an npm package for the first number of days of its release. Most of these seem to be caught within that timeframe (1-3 days). https://gist.github.com/mcollina/b294a6c39ee700d24073c0e5a4e...
What happens when everyone adopts this policy? You just change it to two weeks?
Re: Malicious npm packages detected across Red Hat Cloud Services
#16'No Way to Prevent This,' Says Only package manager Where This Regularly Happens Edit: some people don't understand that it's a defence to https://en.wikipedia.org/wiki/%27No_Way_to_Prevent_This,%27_...
Re: Malicious npm packages detected across Red Hat Cloud Services
#17It does make sense that the right way would be to fork every dependency you use and install from your own repo reviewing and merging from upstream as needed. Would be a giant PITA though. :)
Re: Malicious npm packages detected across Red Hat Cloud Services
#18Re: Malicious npm packages detected across Red Hat Cloud Services
#19Our company uses yarn 4 which has an option to prevent you from installing an npm package for the first number of days of its release. Most of these seem to be caught within that timeframe (1-3 days). https://gist.github.com/mcollina/b294a6c39ee700d24073c0e5a4e...
What happens when everyone adopts this policy? You just change it to two weeks?
Re: Malicious npm packages detected across Red Hat Cloud Services
#20Our company uses yarn 4 which has an option to prevent you from installing an npm package for the first number of days of its release. Most of these seem to be caught within that timeframe (1-3 days). https://gist.github.com/mcollina/b294a6c39ee700d24073c0e5a4e...
What happens when everyone adopts this policy? You just change it to two weeks?