frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Protecting Your Host from Malicious Dependencies

https://www.grepular.com/Protecting_Your_Host_from_Malicious_Dependencies
5•Brajeshwar•1h ago

Comments

sgbeal•36m ago
> To that end, I wrote a python script which isolates npm inside short-lived docker containers.

Somewhat ironically, docker is just as subject to this type of attack as npm, the main difference being that it (usually) has a narrower blast radius.