Imenenja yephakheji ye-NPM 8.15 ikhishwe ngokusekelwa kokuhlolwa kobuqotho bephakheji lendawo

I-GitHub imemezele ukukhululwa komphathi wephakheji ye-NPM 8.15, efakwe ne-Node.js futhi esetshenziselwa ukusabalalisa amamojula e-JavaScript. Kuyaphawulwa ukuthi amaphakheji angaphezu kwezigidigidi ezi-5 alandwa nge-NPM nsuku zonke.

Izinguquko ezibalulekile:

  • Umyalo omusha β€œwesiginesha yocwaningo” ungeziwe ukuze kwenziwe ukuhlolwa kwasendaweni kobuqotho bamaphakheji afakiwe, okungadingi ukukhohliswa ngezinsiza ze-PGP. Indlela entsha yokuqinisekisa isuselwe ekusetshenzisweni kwamasiginesha edijithali asekelwe ku-algorithm ye-ECDSA kanye nokusetshenziswa kwe-HSM (Hardware Security Module) ekuphatheni okuyinhloko. Wonke amaphakheji endaweni ye-NPM asesayiniwe kabusha kusetshenziswa uhlelo olusha.
  • Ukuqinisekiswa kwezinto ezimbili okuthuthukisiwe kumenyezelwe ukuthi kuyatholakala ukuze kusetshenziswe kabanzi. Kwengezwe inqubo yokungena elula neyokushicilela ku-npm CLI, esebenzisa isiphequluli. Uma ucacisa inketho ethi β€œβ€”auth-type=web”, isixhumi esibonakalayo sewebhu esivuleka esipheqululini sisetshenziselwa ukufakazela ubuqiniso be-akhawunti. Amapharamitha esikhathi ayakhunjulwa. Ukusungula iseshini, udinga ukuqinisekisa i-imeyili yakho usebenzisa amagama ayimfihlo esikhathi esisodwa (OTP), futhi lapho wenza imisebenzi kumaseshini asevele esunguliwe, udinga kuphela ukuqinisekisa isigaba sesibili sokuqinisekiswa kwezinto ezimbili. Imodi yokukhumbula inikeziwe, ekuvumela ukuthi wenze imisebenzi yokushicilela phakathi nemizuzu engu-5 ukusuka ku-IP efanayo kanye nethokheni efanayo ngaphandle kokwaziswa okwengeziwe kokuqinisekisa kwezinto ezimbili.
  • Kunikezwe ikhono lokuxhumanisa ama-akhawunti e-GitHub nawe-Twitter ku-NPM, okukuvumela ukuthi uxhume ku-NPM usebenzisa i-akhawunti yakho ye-GitHub ne-Twitter.

Ezinye izinhlelo zisho ukufakwa kokuqinisekiswa kwezinto ezimbili okuyisibopho kuma-akhawunti ahlotshaniswa namaphakheji anokulanda okungaphezu kwesigidi esi-1 ngesonto noma anamaphakheji ancike angaphezu kuka-500. Okwamanje, ukuqinisekiswa kwezinto ezimbili okuyisibopho kusetshenziswa kuphela kumaphakheji aphezulu angama-500.

Source: opennet.ru

Engeza amazwana