Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Issue a warning when repository owner is changed #465

Closed
2 tasks done
ceremcem opened this issue Nov 27, 2018 · 1 comment · Fixed by #621
Closed
2 tasks done

Issue a warning when repository owner is changed #465

ceremcem opened this issue Nov 27, 2018 · 1 comment · Fixed by #621

Comments

@ceremcem
Copy link

  • I have read most of the list of known issues before filing this issue.
  • I have searched for similiar issues before filing this issue. (took a quick look, though)

This is an enhancement request: Due to a security vulnerability message of a dependency package, I took a look at the issue and understand the injection has been performed by a different person, not by the creator of the library.

Original author drops maintaining the library, then someone wants it, he hands it over. The new guy implements a malicious code, publishes it. Currently even the original author has no publish rights on npm.

What I could think of is that: npm-check-updates might warn us when owner is changed, like in the way:

************************************ WARNING ******************************************

This repository's owner has changed. You are advised to check on the new owner. 
Please type the new owner's mail address to continue: ...

************************************ WARNING ******************************************
@raineorshine
Copy link
Owner

Closed with the revive-me tag for interested contributors. See #484.

# for free to join this conversation on GitHub. Already have an account? # to comment
Projects
None yet
2 participants