HNHacker News
TopNewBestAskShowJobs

ethanblackburn

8 karma · joined September 18, 2021

submissionscomments
ethanblackburn··on Show HN: Auto-Unpublish NPM Packages Published Outside CI
Fair points — this isn’t a preventative control and it doesn’t “lock down” your CI. If an attacker has your NPM token, you’ve already been pwned.

The goal is to stop the spread. This will quickly unpublish a library and alert you, so no one else is downloading the compomised package, like what happened with posthog.

ethanblackburn··on Show HN: Tangent – Security log pipeline powered by WASM
Thank you! It was a lot of fun to build