logoalt Hacker News

staticassertionyesterday at 1:50 PM1 replyview on HN

Yeah, NPM should be enforcing 2FA and likely phishing resistant 2FA for some packages/ this should be a real control, issuing public audit events for email address changes, and publish events should include information how it was published (trusted publishing, manual publish, etc).


Replies

erikeriksonyesterday at 2:12 PM

Instead they took away TOTP as a factor.

Scaling security with the popularity of a repo does seem like a good idea.

show 3 replies