qaz@lemmy.world to Selfhosted@lemmy.worldEnglish · 17 hours agoAxios JavaScript library has been compromised with malware in supply chain attackgithub.comexternal-linkmessage-square11fedilinkarrow-up1185arrow-down11
arrow-up1184arrow-down1external-linkAxios JavaScript library has been compromised with malware in supply chain attackgithub.comqaz@lemmy.world to Selfhosted@lemmy.worldEnglish · 17 hours agomessage-square11fedilink
minus-squareEskuero@lemmy.fromshado.wslinkfedilinkEnglisharrow-up28·edit-212 hours agoYou can mitigate similar attacks by editing your .npmrc min-release-age=7 # days ignore-scripts=true
minus-squarePetteriPano@lemmy.worldlinkfedilinkEnglisharrow-up32arrow-down2·12 hours agoIt’s a good way to keep the exploit around for seven days, too, if you apply it right away.
minus-squareEskuero@lemmy.fromshado.wslinkfedilinkEnglisharrow-up2·2 hours agoHow? If you got hit by this you are looking at restoring the system from a safe previous version. And the compromised versions get pulled, not superseeded by a new release, so once you rebuild you would go back to a safe version…
minus-squaretaco_shale032@lemmy.mllinkfedilinkEnglisharrow-up6·12 hours agoI agree, I think it would be better to use something like dependabot or renovatebot so you can know of and apply security updates right away.
minus-squareEskuero@lemmy.fromshado.wslinkfedilinkEnglisharrow-up9·12 hours agoAs long as the bot is not allowed to automatically merge minor version bumps in libraries…
minus-squaremagikmw@piefed.sociallinkfedilinkEnglisharrow-up2·8 hours agoWell yes, one can misuse any tool.
You can mitigate similar attacks by editing your .npmrc
min-release-age=7 # days ignore-scripts=trueIt’s a good way to keep the exploit around for seven days, too, if you apply it right away.
How? If you got hit by this you are looking at restoring the system from a safe previous version.
And the compromised versions get pulled, not superseeded by a new release, so once you rebuild you would go back to a safe version…
I agree, I think it would be better to use something like dependabot or renovatebot so you can know of and apply security updates right away.
As long as the bot is not allowed to automatically merge minor version bumps in libraries…
Well yes, one can misuse any tool.