Rendered at 08:31:43 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
supriyo-biswas 24 minutes ago [-]
Is any form of code analysis out of the question? Static and dynamic analysis of the code would seem like a promising idea rather than just trying to defer the update and hence the problem.
weinzierl 58 minutes ago [-]
Seen favorably, staged publishing is a band aid. Seen more realistically I believe that in the long run it will even hurt our efforts for more secure infra.
buildfocus 29 minutes ago [-]
How could it possibly hurt?
For trusted publishing, it's not a band-aid, it's a significant improvement that kills an entire class of CI takeover publish attacks. I'm sure attackers will find another way but it's a big gap this is closing up.
madarco 19 minutes ago [-]
meanwhile pnpm 10.x by default won't donwload packages younger than a day
stabbles 7 minutes ago [-]
Is one day enough to find vulnerabilities? Who keeps an eye on new releases? Otherwise the problem continues to exist, just delayed by one day.
koinedad 6 hours ago [-]
Nice…maybe will help some of the recent attacks
turkeyboi 5 hours ago [-]
If maintainers actually use it
Klaster_1 5 hours ago [-]
This is the biggest question I also had after reading the blog post. Given the recent chain of attacks, wouldn't it make sense to enforce staged publish by default or at least gradually move over to it?
For trusted publishing, it's not a band-aid, it's a significant improvement that kills an entire class of CI takeover publish attacks. I'm sure attackers will find another way but it's a big gap this is closing up.