The tool was for the toolchain work 7 years ago, maybe if it had continued I've have worked on a bunch of stuff around dependency checking (which I actually did write recently). Like I said I tried to speak up about it then and was shut down by several npm core people so I just moved on instead of spending the energy.
(Everyone seems so focused on the blog post and missing the fact since NPM was created you've been able to manipulate it's postinstall script to install malware - at any level, including npms failure to verify the manifest file)
Comments
The tool was for the toolchain work 7 years ago, maybe if it had continued I've have worked on a bunch of stuff around dependency checking (which I actually did write recently). Like I said I tried to speak up about it then and was shut down by several npm core people so I just moved on instead of spending the energy.
(Everyone seems so focused on the blog post and missing the fact since NPM was created you've been able to manipulate it's postinstall script to install malware - at any level, including npms failure to verify the manifest file)