
705: Is Running Random Code From npm Safe? With Feross Aboukhadijeh
Syntax - Tasty Web Development Treats
Risk of unmaintained open source packages
Open source maintainers may find their packages continue to be used despite lack of active development, and may face unexpected security risks when granting permissions to other contributors. In a specific case, a maintainer granted permissions to help fix critical bugs, only to have the contributor introduce obfuscated code with malicious intent after an initial period of seemingly genuine contributions.
00:00
Transcript
Play full episode
Remember Everything You Learn from Podcasts
Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.