Big news! We’re excited to announce that @npmjs will be joining @GitHub! We're thrilled to join an organization as committed to open source as we are, so that the npm registry can remain free & public forever.
You can read more about this new chapter here: https://t.co/xjInDE46io
Did you ever want to know how a pentester makes their way from bug to exploit? Read about how @truesec found and exploited a bug in hot-formula-parser (CVE-2020-6836)
https://t.co/vopwYujwBF
Great writeup about a remote code execution (RCE) vulnerability in the Strapi framework and the quick response by the Strapi team. https://t.co/dWdzlhFb1d
the npm security team has been hard at work building infrastructure to do behavioral analysis of npm packages at scale. vp of security, @adam_baldwin, explains what this entails (+ a sneak peek at the security insights API): https://t.co/cjgDSgIwTx
We get a lot of requests from people wanting to do research around malware in the Registry. It will be really exciting to see what the community does with this data!
Did you miss us? Well we're back and tweeting. The npm security team has taken over the nodesecurity twitter account and will be keeping you up to date on JavaScript security related happenings.
The Daily Swig speaks to npm’s @adam_baldwin about improving security for the world’s biggest repository of open source software packages
https://t.co/2xi6QEJmUn