Live data from Hacker News

Staged publishing and new install-time controls for npm

github.blog

11–17 of 17 posts

Re: Staged publishing and new install-time controls for npm

#13
post #11

meanwhile pnpm 10.x by default won't donwload packages younger than a day

Is one day enough to find vulnerabilities? Who keeps an eye on new releases? Otherwise the problem continues to exist, just delayed by one day.

There’s almost a dozen cybersecurity companies scanning NPM publishes in real-time and analysing them.

Re: Staged publishing and new install-time controls for npm

#17

Earlier quoted context omitted.

If maintainers actually use it

This is the biggest question I also had after reading the blog post. Given the recent chain of attacks, wouldn't it make sense to enforce staged publish by default or at least gradually move over to it?

[dead]
Post reply on HN