Skip to content

Commit 7d241ed

Browse files
committed
update authors
1 parent 0927892 commit 7d241ed

1 file changed

Lines changed: 3 additions & 1 deletion

File tree

src/blog/incident-followup.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,8 @@ authors:
88
- Corbin Crutchley
99
- Jack Herrington
1010
- Tanner Linsley
11+
- Florian Pellet
12+
- Harry Whorlow
1113
---
1214

1315
This week, fourteen of our packages were republished to npm with malware baked into the published artifacts. The releases were triggered by our normal release pipeline after changes landed on main, but the malicious code was not authored, reviewed, or approved by us. By the time the first report reached our issue tracker, those compromised versions had already been available on the registry for some time.
@@ -49,7 +51,7 @@ The way we had our workflow structured was inevitably how this was attack was ma
4951

5052
Knowing we had added in production is something we have to sit with now. While there are many things we had in place that worked as intended, not being on top of the fact that this pattern was in our workflow is a failure on our part. We had the information we needed to know that this was a potential problem, but we didn't connect the dots to our own setup.
5153

52-
While we can say that the npm provenance, SLSA, OIDC, and 2FA all worked as advertised and still didn't stop this attack, that's not the whole story. The workflow shape itself was the hole, and that's what we're rebuilding now.
54+
While we can say that the npm provenance, SLSA, OIDC, and 2FA all worked as advertised and still didn't stop this attack, that's not the whole story. The workflow shape itself was the hole, and that's what we're rebuilding now.
5355

5456
Modern supply-chain defences are important, but they're not always enough on their own. We have to be more proactive about identifying and closing any holes in our workflows that could be exploited, rather than relying solely on the security features of the tools we use.
5557

0 commit comments

Comments
 (0)