logoalt Hacker News

minitech • yesterday at 3:49 PM • 2 replies • view on HN

To compare it to just one other option: when you run `npx foo`, you know* that you’re getting the same public artifact that anyone else running it at the same time would get. (If you have a `min-release-age` configured, you also benefit from that.) If I wanted to distribute software like this, I’d include npm-shrinkwrap.json; then, with `npx [email protected]`, you could be similarly confident in getting the same app every time.

(I picked this option for ease of comparison, getting a couple of major security wins with very low effort; I don’t recommend `npx`ing stuff in an otherwise unprotected environment either.)

* well, you can be somewhat more sure


Replies

athrowaway3z • yesterday at 4:16 PM

So to be clear; the solution is then something like

`curl https://raw.githubusercontent.com/my/domain/setup.sh | sh`

Note we dont even have a hash there - just a promise that a third party (github) has a log of whatever was hosted at that url.

➕ show 1 reply
slowin • yesterday at 5:00 PM

While I don't think piping curl into bash is the most secure, npm installing has proven time and time again to open yourself up to supply chain attacks. At least with curl you know that you're getting the supply chain put together by the software author. With npm, every single library is a vector for attack every time you update.

➕ show 1 reply