‘No Way to Prevent This’ Says Development Community Where This Regularly Happens
medium.com
medium.com
That sounds like a bug or mis-design in npm, if it's not respecting versions in the lockfile, when no top-level dependency requirements have changed. Isn't the lockfile supposed to... lock?
If you don't allow dependencies to express ranged requirements on their dependencies (your transitive/indirect dependencies), it means that whenever an indirect/transitive dependency releases a security fix, you need to wait on anything in the dependency tree that refers to the fixed thing to release an update, and hope it releases an update without breaking changes for your app.
That doesn't sound like where you want to be.
So while it is possible that npm would modify the lockfile after a fresh clone, the only way that could happen would be if the package.json file was already out of sync with the lockfile on the branch you checked out.
Then why did they change the default behavior to use fuzzy matching? Because someone decided it was the best decision. It isn't about breaking changes, it's about someone's arbitrary decisions and those decisions are arguable.
[0] https://www.theonion.com/no-way-to-prevent-this-says-only-na...
Otherwise it sounds like you could easily be describing something that can’t be prevented.
edit: I also had no idea about the shooting yesterday I tend to stay away from the news as it is far too politicized these days and normally just leaves me angry/unhappy
What the Onion did is a valid, necessary, mildly amusing, but incredibly pointed and powerful criticism of the gun problem in America.
What this article is doing is making that criticism into a punchline in and of itself. That is what is disrespectful.
There are notable problems with how modern software is built with deep dependency graphs and the potential supply chain attacks that are possible because of this, but none of that is exclusive to NPM. NPM has a preference for small single purpose packages and JS is massively popular which might make this problem worse, but it's a problem for a lot more communities and languages than JS/NPM.
0: https://www.reddit.com/r/programming/comments/cjnoqi/no_way_...
1: https://www.reddit.com/r/programming/comments/cjnoqi/no_way_...
Even the ones that haven’t solved the underlying problems have done substantially better jobs mitigating them than NPM. (pip and docker hub are the only counterexamples that come to mind).
Which package mangers and how? The ones I can think of[0] and are familiar with suffer from the same or very similar problems[1].
0: Bundler, Cargo, CocoaPods, Composer, Pip(to a lesser extent)
1: Name squatting, typo squatting, malicious versions via compromised accounts/publishing credentials, compromises to the delivery infrastructure(AFAIK NPM protects against this with the integrity field in package-json.lock)
As for the "how to fix" I suspect the biggest step forward would be creating a decent standard library.
There's actually an active proposal for a standard library, but it is met with a lot of contempt from the JS community [0]
[0] https://github.com/tc39/proposal-javascript-standard-library...
I don't want to swear on HN, so I'll just say .. wow. So there are elements of the community who want to keep the deficiencies there so they can get micro-fame for filling them? People want to feel important by maintaining left-pad?
(also I think they meant moot rather than mute, but hey; also, this is software, we don't really respect idea precedence and any work may be rendered moot by the work of others at almost any time as technology shifts.)
The problem is not that the standard library is bad (It could be shite, it could be gold, it doesn't really matter). The problem is that regardless of what's in your "standard" library, you will have a VERY long tail of users interacting with your code in a user agent that just doesn't support it. Period.
So I think you can rephrase this whole conversation as not "make a better standard library!" but instead as "how do we bootstrap a better standard library into user agents that haven't been updated in 10 years?"
In which case suddenly NPM/Babel/Webpack start to make a lot of sense.
1) I don't know how to do x, lets google it, oh I have to use this _in vogue_ module.
2) oh this module seems to do what I want. _ship_
3) ~two months later~ oh bugger, that has a vulnerability, its not supported any more/API has wildly changed/new owner
I haven't seen data that suggests that NPM malware is more common than most other package managers when you adjust for relative size and rate of new packages.
It's not clear to me how any of the suggested changes that the author proposes would have stopped the last attack, since it likely involved a package author deliberately sabotaging their own package.
The author ignores any of the technical considerations as to why standard libraries are kept small in Javascript. It's an oversimplification of an extremely complicated topic. Javascript has concerns that languages like Python, Ruby, and PHP don't -- namely backwards compatibility and the inability to correct bad decisions once they've been made.
The article is filled with claims that just don't make sense or are outright wrong (unpublishing packages is already not allowed on NPM).
I want to assume the author does actually have experience on the web, and they're not just mad that Javascript/Node exists -- so from a charitable interpretation, this article could have done more to dig into why the recent NPM scare is fundamentally different from similar situations that have popped up recently in, say, Ruby Gems[0].
The Onion wasn't joking with their article. Satire isn't just about humor (though it sometimes leverages it). This author entirely missed the point of what the Onion did and should really re-think if this is something they want to be associated with.
It's entirely appropriate to talk about gun control and gun reform, all the time - even (and especially) immediately after a mass shooting. It's never appropriate to turn the mass shooting tragedy into a punchline for to get more clicks on your article.
1: https://www.theonion.com/search?blogId=1636079510&q=%E2%80%9...
I mean, why argue for _not_ having a standard library?
Yeah, it was just a parody of the articles The Onion regularly releases regarding another topic and to be honest I didn't quite expect my post to take off the way it did.
I'm also sorry I posted it on Medium, which I personally dislike, but since Medium is frequented by many JS devs it seemed the ideal place to put that joke.