JavaScript Archives - Software Engineering Daily cover image

JavaScript Supply Chain with Feross Aboukhadijeh

JavaScript Archives - Software Engineering Daily

00:00

Is There a Reproducible Build?

With a reproducible build, anyone can go and take the source code, build it and get the exact same bit for bit output as the maintainer would have gotten. And so they can confirm that nothing sneaky was added to the result. typo squatting is when someone registers a package with a name that's very similar to a popular package. You make a one letter mistake and ask suddenly you're executing code from some random package that no one has ever even looked at before. That's really bad. I don't know why the existing tooling doesn't do it. It's something that like the number one supply chain attack vector right now that we're seeing. We just keep thinking of

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app