• davidgro@lemmy.world
    link
    fedilink
    English
    arrow-up
    7
    ·
    1 day ago

    My understanding is that for most package managers the signing keys are held by a smallish number of maintainers responsible for entire sections, who presumably keep those accounts pretty tightly secured. Not impossible to take over, but it’s a smaller attack surface.

    While for NPM as far as I know every uploader keeps their own account and there’s not even signing keys to lose control of.

    • hirihit640@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      3
      ·
      7 hours ago

      I’ve heard quite a few PyPi and Cargo attacks though, but I bet the main reason why hear NPM so much is simply because NPM is the biggest, and thus the most valuable target