-
Notifications
You must be signed in to change notification settings - Fork 3.7k
Description
Is there an existing issue for this?
- I have searched the existing issues
This issue exists in the latest npm version
- I am using the latest npm
Current Behavior
Subsequent malware attacks and security issues in the npm supply chain
Recently, the npm ecosystem has suffered several supply chain attacks shortly after its launch, and this has been widely reported in the Spanish-speaking community by people like midudev 🧐👍😄
Apart from removing the carets, we have no other option, but it doesn't solve the underlying problem. I created my own implementation for my private projects, which isn't the best solution, but it works for me for now. However, I would like to know how we can collaborate or contribute to making the npm platform, which is the benchmark in the nodejs ecosystem, more secure for all of us who use it and the community in general.
Finally, I would appreciate it if you could indicate if you have already contacted an issue regarding this specific topic. 😎
Environment
- npm:11.5.2
- Node.js: v22.19.0
- OS Name: Fedora Linux 42
- System Model Name:Lenovo IdeaPad Core i7-13620H