GitHub’s commitment to NPM ecosystem security
github.blog
github.blog
"This vulnerability existed in the npm registry beyond the timeframe for which we have telemetry to determine whether it has ever been exploited maliciously. However, we can say with high confidence that this vulnerability has not been exploited maliciously during the timeframe for which we have available telemetry, which goes back to September 2020."
Any version of any npm package published before September 2020 could have been tampered with by anyone aware of that exploit and no-one would be any the wiser. That is pretty bad news.
Pretty big screw up.
Like BP writing about environmental commitment after deep water horizon
I was so confused that the article title and content mention "GitHub" a few times. I was like "How is forcing 2FA on GitHub" address the problem for NPM?
> As stewards of the registry, the security and trustworthiness of npm is crucial to all of us at GitHub And this made me thought the vulnerable npm packages could get into github internal systems.
> Transparency is key in maintaining the trust of our community
and then proceeds with apparently a bit trying to hide the dangerous bug, behind a wall of text.