You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
What threads we think of when we design our tool and process.
4
+
5
+
## Stealing maintainer credentials
6
+
7
+
> Attacker put malware to PostCSS `devDependencies` so maintainer will be injected and their credentials will be stolen to put malware now in this package.
8
+
9
+
Solutions:
10
+
11
+
1. We are working only in Dev Container. Attacker will have very limited access to host.
12
+
2.`npm` 2FA is on hardware token, so even maintainer machine compromising will not lead to leaking full-time credentials.
13
+
14
+
## Malware in nested dependencies
15
+
16
+
> The tool’s dependencies will be hijacked and malware will be installed to all tool’s users.
17
+
18
+
Solutions:
19
+
20
+
1. We use only dependencies without own dependencies.
21
+
2. We try to reduce dependencies as much as possible.
22
+
23
+
## Malware from development dependencies
24
+
25
+
> Malware in tool’s dependencies can write some script into the tool’s source code. A maintainer releases it unnoticed.
26
+
27
+
Solutions:
28
+
29
+
1. For development we use `pnpm` without a `postinstall` script.
30
+
2. We use `pnpm` with [`minimumReleaseAge`](https://pnpm.io/supply-chain-security#delay-dependency-updates) with 1 day cool down.
31
+
3. We are using lockfile for pnpm and also for GitHub Actions.
0 commit comments