npm under siege (what to do about it) (Friends)

npm遭受攻击(如何应对)(朋友)

The Changelog: Software Development, Open Source

2025-10-04

1 小时 35 分钟
PDF

单集简介 ...

Over the past two months, we’ve seen some of the most serious supply chain attacks in npm history: phishing campaigns, maintainer account takeovers, and malware published to packages with billions of weekly downloads. What is going on?! What can we do about it? Our old friend, Feross Aboukhadijeh, joins us to help make sense of it all.
更多

单集文稿 ...

  • Welcome to changelog and friends, a weekly talk show about exfiltrating CLOD tokens.

  • Thank you to our sponsors at fly.io, the public cloud built for developers who like to ship.

  • We love Fly.

  • You might too.

  • Check them out at fly.io.

  • Okay, let's talk.

  • What's up, friends?

  • I'm here with Kyle Galbraith, co-founder and CEO of Depot.

  • Depot is the only build platform looking to make your builds as fast as possible.

  • But Kyle, this is an issue because GitHub Actions is the number one CI provider out there,

  • but not everyone's a fan.

  • Explain that.

  • I think when you're thinking about GitHub actions,

  • it's really quite jarring how you can have such a wildly popular CI provider.

  • And yet it's lacking some of the basic functionality or tools that you need to actually be able to debug your builds or deployments.

  • And so back in June,

  • we essentially took a stab at that problem in particular with Depot's GitHub action runners.

  • What we've observed over time is effectively GitHub actions when it comes to like actually debugging a build is pretty much useless.

  • The job logs in GitHub Actions UI is pretty much where your dreams go to die.

  • Like they're collapsed by default.