Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FEATURE REQUEST] Supply Chain Security Analisys #1628

Open
elliot-huffman opened this issue May 3, 2024 · 1 comment
Open

[FEATURE REQUEST] Supply Chain Security Analisys #1628

elliot-huffman opened this issue May 3, 2024 · 1 comment

Comments

@elliot-huffman
Copy link
Contributor

Is your feature request related to a problem? If so, please give a short summary of the problem and how the feature would resolve it
Having a supply chain analysis solution to identify potential supply chain attacks is now more important than ever with attacks like the recent attempted XZ attack.
Because of this, we need to up our defenses against nation state threat actors attacking us directly or through our dependencies.
This project is a larger one with ~1.4million downloads a week. A threat actor would love to breach this.

Describe the preferred solution
Integrate https://socket.dev/ into this project.
Socket is free for open-source projects, like this one :)
I would make a PR for this, but it runs as a GitHub App/bot, and I don't have the permissions to turn it on.

Describe alternatives you've considered
Getting hacked eventually, lol

Additional context
https://en.wikipedia.org/wiki/XZ_Utils_backdoor
https://www.bleepingcomputer.com/news/security/red-hat-warns-of-backdoor-in-xz-tools-used-by-most-linux-distros/
https://socket.dev/npm/package/tedious

Reference Documentations/Specifications
https://docs.socket.dev/docs/getting-started
https://socket.dev/features/github

@MichaelSun90
Copy link
Contributor

Thanks for the explanation and background information! will spend some time on catching up on the background readings.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants