Remote
Marcel Koch
@m@social.rcelko.ch
Software architect & trainer. I build long-lived systems: one stable domain core, swappable tech around it.
#CrossPlatform · #SoftwareArchitecture · #CleanArchitecture · 🦀 #RustLang
Also into #psychology, communication, and music. Opinions are my own and sometimes uncomfortable.
#CrossPlatform · #SoftwareArchitecture · #CleanArchitecture · 🦀 #RustLang
Also into #psychology, communication, and music. Opinions are my own and sometimes uncomfortable.
73 Followers
72 Following
14 Posts
Website:
LinkedIn:
Open post
Open post
Open post
Open post
New #just recipe in my home directory: `unchain_librewolf: xattr -dr com.apple.quarantine /Applications/LibreWolf.app #librewolf #homebrew #macos
0
0
0
0
Open post
Recent npm worms bring me to the question:
What can developers and IT people do to reduce your risk of such issues?
1. Version Pinning & Lock Files
Use npm ci instead of npm install to prevent unexpected version changes.
Commit package-lock.json to version control and avoid floating version ranges (^, ~).
2. Package Verification
Check signatures with npm audit signatures and use Provenance Attestation for verified builds.
Wait 24-48 hours before adopting new versions - many attacks are detected in this window.
Use tools like Socket, Snyk, or GuardDog to scan for malicious packages.
3. Account Security
Enable 2FA with write protection for npm accounts.
Avoid classic tokens - use short-lived OIDC tokens (e.g., via GitHub Actions).
Secure your laptop with full-disk encryption and a password manager.
4. CI/CD Security
Disable postinstall scripts in CI with --ignore-scripts.
Segment secrets using the least-privilege principle - not every job needs access to all tokens.
No system is perfect, but these steps make attacks much harder. And this isn't just about npm or Node.js. Supply chain risks exist in every ecosystem, including Rust and Cargo.
Stay vigilant - and feel free to share your own best practices!
#CyberSecurity #SupplyChainSecurity #DevSecOps #SoftwareDevelopment
What can developers and IT people do to reduce your risk of such issues?
1. Version Pinning & Lock Files
Use npm ci instead of npm install to prevent unexpected version changes.
Commit package-lock.json to version control and avoid floating version ranges (^, ~).
2. Package Verification
Check signatures with npm audit signatures and use Provenance Attestation for verified builds.
Wait 24-48 hours before adopting new versions - many attacks are detected in this window.
Use tools like Socket, Snyk, or GuardDog to scan for malicious packages.
3. Account Security
Enable 2FA with write protection for npm accounts.
Avoid classic tokens - use short-lived OIDC tokens (e.g., via GitHub Actions).
Secure your laptop with full-disk encryption and a password manager.
4. CI/CD Security
Disable postinstall scripts in CI with --ignore-scripts.
Segment secrets using the least-privilege principle - not every job needs access to all tokens.
No system is perfect, but these steps make attacks much harder. And this isn't just about npm or Node.js. Supply chain risks exist in every ecosystem, including Rust and Cargo.
Stay vigilant - and feel free to share your own best practices!
#CyberSecurity #SupplyChainSecurity #DevSecOps #SoftwareDevelopment
0
0
0
0
Open post
Open post
One application core for all platforms
A single application spanning mobile, desktop, web, and even embedded.
Rust makes this practical by enabling a durable, flexible and testable application core.
In part 2 of this series, I show how this can be implemented using Crux.
https://www.heise.de/en/background/Cross-Platform-Applications-with-Rust-2-Crux-in-Use-11166058.html
#Rust #SoftwareArchitecture #crossplatform #WebAssembly #Embedded
A single application spanning mobile, desktop, web, and even embedded.
Rust makes this practical by enabling a durable, flexible and testable application core.
In part 2 of this series, I show how this can be implemented using Crux.
https://www.heise.de/en/background/Cross-Platform-Applications-with-Rust-2-Crux-in-Use-11166058.html
#Rust #SoftwareArchitecture #crossplatform #WebAssembly #Embedded
0
0
0
0
Open post
Why are in the fediverse? Why do you use social networks?
0
0
0
0
Open post