HNHacker News
TopNewBestAskShowJobs

TheRealBrianF

5 karma · joined November 4, 2021

submissionscomments
TheRealBrianF··on Open Infrastructure Is Not Free: A Joint Statement on Sustainable Stewardship
I think you're obliquely referring to me there.

I covered some of this in one of my previous blogs where i talked about the systemic challenges here that I've uncovered. The heavy users that I spoke to, 100% of them had a repository manager, some Nexus, others Artifactory. And yet the high levels of consumption still persisted. I discussed some of the reasons for this in the blog link below... but I think this refutes the theory that simply having yet another caching proxy solves the problem. It really doesn't. Additionally as Mike discussed, bandwidth is only part of the challenge. Without the people behind the repositories doing the malware response, the curation of namespaces etc, there wouldn't be anything to proxy anyway.

https://www.sonatype.com/blog/free-isnt-free-the-hidden-cost...

TheRealBrianF··on Snyk security researcher deploys malicious NPM packages targeting cursor.com
You're referring to what I described previously here... ironically back when the first dependency confusion research was published: https://www.sonatype.com/blog/why-namespacing-matters-in-pub...
TheRealBrianF··on Ask HN: How do you security-audit external software using NPM packages?
Sonatype Lifecycle is designed to analyze a built package and figure out what's inside it, specifically when there aren't manifest files to tell you what's -supposed- to be there. It can obviously do a lot more, but the analysis is designed to solve the exact problem you're describing.

https://blog.sonatype.com/mapping-the-javascript-genome-for-...