I thought npm was simply a package manager - I don't see anything in the article that is specific to npm, except he happens to say that word.
I thought npm was simply a package manager - I don't see anything in the article that is specific to npm, except he happens to say that word.
Two is that much of it is expected to be served to the browser, so it's minified. Who audits that the minified code is actually the same as the published Github code?
At least in Ruby and Python, the code from Rubygems/Pip should exactly match that version on Github. Not that anyone necessarily audits that either, but at least it's easier.
Otherwise, yes this is a fundamental dependency issue.
that's the same for any javascript package manager - yarn or bower would be the same.
im a total noob at security, please attack/modify this idea if it has any value?
I question all these comments by people singling out npm as the root of the problem. doesn't sound to me like they fully understand the issue.
The next problem is that npmjs is "free for all". Imagine anyone could easily add new packages to the debian repo. Sure, I don't expect the debian folks to audit every new addition or update to existing packages, but there is at least some chain of trust, plus there is some incentive to not have malware ridden packages in your distro because it hurts your credibility. A distro is both, an infrastructure and content provider. npmjs is just the infrastructure, so it takes some more messups for people to consider moving away from it.
This same problem would exist if any server-side dependency repositories allow for code to be delivered in a pre-compiled form without any verification, similar to npmjs.