Skip to content

Security: reject 3rd unsigned party binaries #682

@taelfrinn

Description

@taelfrinn

It seems like this would be a nice feature if the binaries were signed by red hat etc, but unsigned or nobody-i-know signed 3rd party binaries are generally unacceptable.

perhaps we could honor a global npm config option to make "--build-from-source" default behavior?

It seems to make normal nodejs development inherently insecure when any npm library can suddenly start shipping black boxes... and only a matter of time before it gets widely exploited...

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions