|
|
Log in / Subscribe / Register

Is this our chance to stop using NPM?

Is this our chance to stop using NPM?

Posted Jun 2, 2026 22:29 UTC (Tue) by dsommers (subscriber, #55274)
In reply to: Is this our chance to stop using NPM? by mathstuf
Parent article: Multiple redhat-cloud-services npm packages compromised (StepSecurity Blog)

A compromised GH account is likely. But it might also include an API token key approach, where 2FA does not help much.

Signed commits, tags and pushes, which would need to be verified to complete a build process, is one good way. Or pulling two (or more) independent git repositories (not automatically mirrored ones) and verify branches/tags matches would be another way.


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds