>> high-impact npm accounts are now put into a read-only mode for 72 hours when they change their email or use a 2FA recovery code. This delay allows maintainers time to respond and recover the account before their account can be used to start an attack.<p>'what time shall we put here?'<p>'what's the longest hangover you ever had?'<p>'let's put 72 hours'
Github owns NPM. Github has unprecedented access to code analysis tools. Github can run static analysis on nearly everything. Introducing a cooldown period seems like the lowest tech solution to a technological problem I have seen in a longwhile.
One thing I don't quite get is how trusted publishing is supposed to be more secure. It still allows publishing if they pwn your workflow.<p>Is it purely more secure because they can't exfiltrate your secret keys to publish again?<p>I feel like if your workflow gets pwned you'd be rotating your keys anyways, so I'm not sure if the vendor lock-in is worth it.
Trusted <i>staged</i> publishing helps a lot: you have to independently pwn the workflow _and_ then complete a separate 2FA flow as a maintainer. The workflow never sees any keys that can publish independently.
Keys can be reused from anywhere. Trusted publishing means the attacker must trigger the specific workflow <i>on GitHub</i>, which is more difficult and leaves trace of actions on GitHub itself.
Been quietly thinking this for years
[flagged]
[flagged]
The job can require you to
[flagged]
These comments should be removed r from HN, because they in no way actually add to the conversation. They aren’t intelligent, they aren’t insightful, they aren’t actionable, and they don’t invite a genuine reply. All you’re saying is that you happen to not use these technologies yourself – something that I’m sure is only by happenstance – and that you feel superior for it.<p>This is a blog post by GitHub. what are you suggesting that these employees do? Simply ignore that they exist? Regardless of whether or not you use them, they still exist.
This is such a myopic take
GitHub actions doesn’t really make you a js shop
> Opting out of toxic ecosystems is a valid option<p>Quick, everyone break out the pitchforks for a valid analysis of a game! /s
the bare minimum award, for the only language and only registry where this regularly happens.