https://github.com/wesleytodd
> Their write up highlights how subtle CI workflow choices can create a path from untrusted contributions to package release credentials.
via @socket.dev ☝️ socket.dev/blog/shai-hu...
> Their write up highlights how subtle CI workflow choices can create a path from untrusted contributions to package release credentials.
via @socket.dev ☝️ socket.dev/blog/shai-hu...
We should not have a system that requires our MASSIVE base of volunteer maintainers to know all of this to secure our supply chain. That is not scalable, nor is it necessary.
OIDC and token-based publishing are default insecure, full stop.
We should not have a system that requires our MASSIVE base of volunteer maintainers to know all of this to secure our supply chain. That is not scalable, nor is it necessary.
Their release still doesn't have an environment: github.com/asyncapi/cli...
Their release still doesn't have an environment: github.com/asyncapi/cli...
The much more reasonable approach is to ensure malicious automated publish is *hard*.
The much more reasonable approach is to ensure malicious automated publish is *hard*.
bsky.app/profile/notw...
Y'all I am tired.
bsky.app/profile/notw...
I want to be able to stop having this discussion every other week and go into the new year without more supply chain incidents over the holidays.
I want to be able to stop having this discussion every other week and go into the new year without more supply chain incidents over the holidays.
Feel free to tell @github.com we want them to enforce 2FA on all publishes to @npmjs.bsky.social.
Feel free to tell @github.com we want them to enforce 2FA on all publishes to @npmjs.bsky.social.
2FA is just right there, it stops this in it's tracks, and @github.com refusing to enforce it is a massive problem.
2FA is just right there, it stops this in it's tracks, and @github.com refusing to enforce it is a massive problem.
Y'all I am tired.
Y'all I am tired.
github.com/npm-pub-2025...
github.com/npm-pub-2025...