Skip to content

Commit 3ee79a2

Browse files
authored
Thread model (#2071)
* Create incident response docs * Add thread model
1 parent 2e0683d commit 3ee79a2

1 file changed

Lines changed: 31 additions & 0 deletions

File tree

‎docs/THREAD_MODEL.md‎

Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
# Thread Model
2+
3+
What threads we think of when we design our tool and process.
4+
5+
## Stealing maintainer credentials
6+
7+
> Attacker put malware to PostCSS `devDependencies` so maintainer will be injected and their credentials will be stolen to put malware now in this package.
8+
9+
Solutions:
10+
11+
1. We are working only in Dev Container. Attacker will have very limited access to host.
12+
2. `npm` 2FA is on hardware token, so even maintainer machine compromising will not lead to leaking full-time credentials.
13+
14+
## Malware in nested dependencies
15+
16+
> The tool’s dependencies will be hijacked and malware will be installed to all tool’s users.
17+
18+
Solutions:
19+
20+
1. We use only dependencies without own dependencies.
21+
2. We try to reduce dependencies as much as possible.
22+
23+
## Malware from development dependencies
24+
25+
> Malware in tool’s dependencies can write some script into the tool’s source code. A maintainer releases it unnoticed.
26+
27+
Solutions:
28+
29+
1. For development we use `pnpm` without a `postinstall` script.
30+
2. We use `pnpm` with [`minimumReleaseAge`](https://pnpm.io/supply-chain-security#delay-dependency-updates) with 1 day cool down.
31+
3. We are using lockfile for pnpm and also for GitHub Actions.

0 commit comments

Comments
 (0)