Hacker News new | ask | show | jobs
by Forge36 2961 days ago
Why not a whitelist of users who can make changes to code flagged as security sensitive (or more specifically: security-authentication)?

Edit: digging through Reddit comments more suggests the repo owner may have been hacked as commit blame shows his user made the changes. In this case: a Blacklist wouldn't help and my suggestion may already be in place.

1 comments

It doesn't matter if it's "security sensitive" or not. Any compromised package can steal your secrets.