|
|
|
|
|
by BenjaminCoe
3740 days ago
|
|
Similar problems exist in most package management systems. registries that have a manual review process mitigate this danger, but there's still always a risk of malicious code getting into the world. Having said this, we'd like to make exploits such as those discussed in #319816 as difficult as possible. We're exploring supporting new authentication strategies: such as 2-factor authentication, SAML, and asymmetric key based authentication (some of these features are already available in our Enterprise product, but haven't made it to the public registry yet). npm's official response has more details on this subject: http://blog.npmjs.org/post/141702881055/package-install-scri... |
|
Linux package managers are a different story of course.