Urgent.News

What's breaking now, across thousands of outlets.

Tech

(Rant) Provenance and npm packages

Here's the thing about me. I'm an overbearing asshole. As such, I don't really like npm. No good reason to speak of. I've dabble with yarn and pnpm, and internal npm registries, and lockfiles and sha hashes and IPFS and all that. I've gone a long time from actually using npm proper. Like, the public npm registry. And I had seen the yarn npm registry (mirror?). I'm like... "that's cool, but how…

The author expresses frustration with the npm package manager, stating that they rarely use it despite dabbling with alternatives like Yarn and Pnpm. They criticize npm for its lack of built-in mechanisms for ensuring package integrity, such as verifying that a package was built correctly from source code. The author suggests that npm allows package authors to upload whatever they want without checking, and that security researchers have developed scripts to compare the output of GitHub repositories to their public npm packages to detect malicious publishing.

However, they argue that these measures are not sufficient to ensure security. The author advocates for provenance, which is a clear signal that the package was built from source code and can be traced back to its original source. They note that GitHub has begun displaying provenance badges in their packages, which provide metadata about the build process.

The author believes that provenance is a crucial step towards ensuring the security and reliability of npm packages, but acknowledges that it can be difficult to implement and understand.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

What if an unstable aircraft approach could be identified early enough for a flight instructor to intervene?

What if an unstable aircraft approach could be identified early enough for a flight instructor to intervene? That is the problem behind this open source project: AI Early Warning for Unstable…

  • AI Early Warning system analyzes general aviation training approaches
  • Detects potential instability using sink rate and speed rules
  • Instructor review crucial due to ADS-B measurement limitations

Cheap App Logging for Small SaaS: Compare Hosted and Self-Hosted Failure Signals

Short answer: for a small SaaS notification service, the best inexpensive logging choice is the one that preserves enough evidence to reconstruct a failed delivery without turning every retry into a…

  • Compare Datadog, Better Stack, Logtail, Axiom, and self-hosted Loki for small SaaS logging.
  • Prioritize log quality over cost, including essential info, no sensitive data.
  • Use idempotent submissions, structured fields, and consistent naming scheme.

More from Monday 5 October →