Daily Shaarli

All links of one day in a single page.

April 13, 2016

"Defeating The Npm Worm", David Bruant

"There is a security vulnerability in npm by default that enables writing a worm that can propagate to anyone doing an npm install to a package that would contain an infected dependency (even if the dependency is deep)."

"GitHub’s CSP journey", Patrick Toomey

"In this post we will focus on our ever evolving use of Content Security Policy (CSP), as it is our single most effective mitigation. We can’t wait to follow up on this blog to additionally review some of the “non-traditional” approaches we have taken to further mitigate content injection."