←back to thread

1208 points jamesberthoty | 1 comments | | HN request time: 0s | source
Show context
kelnos ◴[] No.45266878[source]
As a user of npm-hosted packages in my own projects, I'm not really sure what to do to protect myself. It's not feasible for me to audit every single one of my dependencies, and every one of my dependencies' dependencies, and so on. Even if I had the time to do that, I'm not a typescript/javascript expert, and I'm certain there are a lot of obfuscated things that an attacker could do that I wouldn't realize was embedded malware.

One thing I was thinking of was sort of a "delayed" mode to updating my own dependencies. The idea is that when I want to update my dependencies, instead of updating to the absolute latest version available of everything, it updates to versions that were released no more than some configurable amount of time ago. As a maintainer, I could decide that a package that's been out in the wild for at least 6 weeks is less likely to have unnoticed malware in it than one that was released just yesterday.

Obviously this is not a perfect fix, as there's no guarantee that the delay time I specify is enough for any particular package. And I'd want the tool to present me with options sometimes: e.g. if my current version of a dep has a vulnerability, and the fix for it came out a few days ago, I might choose to update to it (better eliminate the known vulnerability than refuse to update for fear of an unknown one) rather than wait until it's older than my threshold.

replies(35): >>45266995 #>>45267024 #>>45267360 #>>45267489 #>>45267600 #>>45267697 #>>45267722 #>>45267967 #>>45268218 #>>45268503 #>>45268654 #>>45268764 #>>45269143 #>>45269397 #>>45269398 #>>45269524 #>>45269799 #>>45269945 #>>45270082 #>>45270083 #>>45270420 #>>45270708 #>>45270917 #>>45270938 #>>45272063 #>>45272548 #>>45273074 #>>45273291 #>>45273321 #>>45273387 #>>45273513 #>>45273935 #>>45274324 #>>45275452 #>>45277692 #
homebrewer ◴[] No.45268503[source]
Don't update your dependencies manually. Setup renovate to do it for you, with a delay of at least a couple of weeks, and enable vulnerability alerts so that it opens PRs for publicly known vulnerabilities without delay

https://docs.renovatebot.com/configuration-options/#minimumr...

https://docs.renovatebot.com/presets-default/#enablevulnerab...

replies(1): >>45269456 #
collinmanderson ◴[] No.45269456[source]
Why was this comment downvoted? Please explain why you disagree.
replies(1): >>45269990 #
biggusdickus69 ◴[] No.45269990[source]
I didn’t downvote, but...

Depending on a commercial service is out of the question for most open source projects.

replies(1): >>45271839 #
isbvhodnvemrwvn ◴[] No.45271839{3}[source]
Renovate is not commercial, it's an own source dependabot, quite more copable at that.
replies(1): >>45272364 #
wereHamster ◴[] No.45272364{4}[source]
AGPL is a no-go for many companies (even when it's just a tool that touches your code and not a dependency you link to).
replies(1): >>45274342 #
1. 1oooqooq ◴[] No.45274342{5}[source]
good. that's the point.

agpl is a no go for companies not intending to ever contribute anything back. good riddance.