You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
OpenSSF released Principles for Package Repository Security which addresses package registries themselves, but could be helpful in providing idea and insights in terms of safe-guards to watch out for that could be automated with npq.
For example: To prevent domain resurrection for account takeover via the recovery process, the package repository detects abandoned email domains. This may look like doing a WHOIS lookup on all registered email domains, and removing the ability to recover an account via an email domain that has been abandoned.
The text was updated successfully, but these errors were encountered:
OpenSSF released Principles for Package Repository Security which addresses package registries themselves, but could be helpful in providing idea and insights in terms of safe-guards to watch out for that could be automated with npq.
For example:
To prevent domain resurrection for account takeover via the recovery process, the package repository detects abandoned email domains. This may look like doing a WHOIS lookup on all registered email domains, and removing the ability to recover an account via an email domain that has been abandoned.
The text was updated successfully, but these errors were encountered: