Looks good? But doesn't this just change the compromise window from first installation to first run?
Upcoming breaking changes for npm v12
11–20 of 221 posts
Re: Upcoming breaking changes for npm v12
#12didn't know npm was owned by github.. well, that explains things...
Some of it aged... interesting.
Top comment:
> Microsoft doesn’t do everything right but the GitHub acquisition has honestly gone better than I ever expected. Rather than forcing GitHub to adopt Microsoft centric policies, Microsoft has adopted more GitHub stuff, especially from a product POV. GitHub still runs as a separate company (different logins and health care and hiring systems) with its own policies and point of view.
> ...
Re: Upcoming breaking changes for npm v12
#13Looks good? But doesn't this just change the compromise window from first installation to first run?
Without that, this just comes across like unconstructive commentary.
This moves the needle a little your proposals or the lack thereof don’t move it at all. So I’ll take this over nothing.
Re: Upcoming breaking changes for npm v12
#14They should have added a 1-day age limit by default, so security scanners have some time.
A better safety net would be to require active 2FA proof for every package update.
Re: Upcoming breaking changes for npm v12
#15Looks good? But doesn't this just change the compromise window from first installation to first run?
I’m sure we’d all welcome your alternative and or superior proposals. Without that, this just comes across like unconstructive commentary. This moves the needle a little your proposals or the lack thereof don’t move it at all. So I’ll take this over nothing.
Re: Upcoming breaking changes for npm v12
#16Looks good? But doesn't this just change the compromise window from first installation to first run?
Re: Upcoming breaking changes for npm v12
#17They should have added a 1-day age limit by default, so security scanners have some time.
I don't think it'd necessarily be a good decision, sometimes CVE are actively exploited and need quick patching. A better safety net would be to require active 2FA proof for every package update.
Re: Upcoming breaking changes for npm v12
#18Re: Upcoming breaking changes for npm v12
#19Looks good? But doesn't this just change the compromise window from first installation to first run?
The dev has to be responsible for ensuring that their build scripts are safe, I need to be responsible for ensuring that my runtime is safe.
It'd be great to have more tools for untrusting libraries (iframes are awesome for this on the frontend) but this is still a massive win.
Re: Upcoming breaking changes for npm v12
#20Earlier quoted context omitted.
Hahaha that's amazing, just a big red "RETIRED" badge above their blog post? What the hell
Breaking changes have had that tag for ages