What's Going on Inside Your Node_modules Folder?
socket.dev
socket.dev
Majority are benign, but when a package without one adds one, you probably want to see why :)
f-droid distributes builds they run themselves from github, which depending on your trust model, is either better or worse than letting authors upload binaries, but at least shows awareness of the problem
trusted CI for software will be a big deal -- it doesn't have to be open source, but in the case of a breach you should be able to have a trusted third party check the source code for your binary and rule out foul play
we should also be incentivizing ($) expert code review of high-traffic packages -- I suspect this happens informally already (remember how big cos got serious about ssl post snowden), but would be nice to formalize
Looks like an awesome tool, actually.
That's my understanding of it anyway.
I think it's also just a footgun of the JS community. People tend to jump to "what package do I need to install for this" much quicker instead of thinking "how can I solve this".
Every recent JS developer that is learning through online material is constantly berated with "just install this dep, and this dep, and then this one", to the point where it's normalized to have a dependency that comes with who knows what for something that could be a few lines of code and maybe some witty google-foo.
Regardless, even in case of package managers that don't have install scripts (e.g. Maven) one could simply insert malware directly into library code and have it execute whenever you run tests or your application.
The only true solution would be some sort of sophisticated sandboxing or sophisticated malware detection or distributed code review.
The ~/.gradle/caches isn’t something to write home about either.
I did just check my ~/.gradle is 17G, I can probably delete Gradle 4.0, 4.1, 4.8, 5.0... thanks for the reminder! =)
This is the same problem for Go and other package managers right? I guess the best defence is some npm install alternative that runs a check against a trusted registry of modules that have been audited. Does that exist already?