Hopefully something like google signed http exchange will fix that in the future for browsers at least.
Hopefully something like google signed http exchange will fix that in the future for browsers at least.
https://medium.com/binary-passion/gentlemen-please-fasten-yo...
Libraries were added manually by legions of developers long before one thought he'd need to create a downloadable left-pad "package".
The whole package management issue is overrated.
You can trust that the developer meant to release that, and it's not some hack of the system, and you can also require that the code comes from a vetting third party that reviews all modules and updates and signs it itself (i.e. what Linux distro package managers do).
- Host can change what is in a package at any time. In case Deno calculates a hash on your machine (e.g. package-lock.json), it's not as bad, but still without a signed package you can't be sure that it was the author that released the code in the first place.
- Host <-> CDN usually happens over HTTP. Often it is the CDN where HTTPS is terminated. Technically the CDN can deliver whatever code to you.
- Corporate HTTPS proxies exist. With a proxy like this, it can also replace the code with whatever it likes.
If you trust the URL is in a (sub)domain controlled by the author and it's a HTTPS URL, that's as much guarantee as a signature.