Disrupting supply chain attacks on NPM and GitHub Actions

(github.blog)

35 points | by nyku 2 hours ago

4 comments

  • alpineman 23 minutes ago
    >> high-impact npm accounts are now put into a read-only mode for 72 hours when they change their email or use a 2FA recovery code. This delay allows maintainers time to respond and recover the account before their account can be used to start an attack.

    'what time shall we put here?'

    'what's the longest hangover you ever had?'

    'let's put 72 hours'

  • pluto_modadic 7 minutes ago
    the bare minimum award, for the only language and only registry where this regularly happens.
  • hncsiocp9x 19 minutes ago
    Been quietly thinking this for years
  • DiabloD3 1 hour ago
    [flagged]
    • theF00l 1 hour ago
      The job can require you to
      • DiabloD3 1 hour ago
        [flagged]
        • UqWBcuFx6NV4r 43 minutes ago
          These comments should be removed r from HN, because they in no way actually add to the conversation. They aren’t intelligent, they aren’t insightful, they aren’t actionable, and they don’t invite a genuine reply. All you’re saying is that you happen to not use these technologies yourself – something that I’m sure is only by happenstance – and that you feel superior for it.

          This is a blog post by GitHub. what are you suggesting that these employees do? Simply ignore that they exist? Regardless of whether or not you use them, they still exist.

          • anon48293 33 minutes ago
            > This is a blog post by GitHub. what are you suggesting that these employees do? Simply ignore that they exist?

            The buggy, insecure feature that is GitHub actions? Yes, preferably so.

        • x86a 1 hour ago
          This is such a myopic take
        • baby_souffle 57 minutes ago
          GitHub actions doesn’t really make you a js shop
    • rho138 1 hour ago
      > Opting out of toxic ecosystems is a valid option

      Quick, everyone break out the pitchforks for a valid analysis of a game! /s