Skip to content

[Bug]: too many collaborators on npm package #1200

@benmccann

Description

@benmccann

Bug Description

I can't count how many people have access to publish @zapier/zapier-sdk, which is probably a big driver of how it was compromised.

You should reduce the number of tokens with publish access. One way to do this would be to setup a tool like changesets to handle publishing so that only the tool has access rather than so many individual accounts

I would also recommend setting up OIDC publishing and package provenance

Reproduction Steps

Visit https://www.npmjs.com/package/@zapier/zapier-sdk. Look at collaborators section

Zapier Platform version

all

Node.js version

all

Your Operating System

No response

npm/yarn version

No response

App ID

No response

More Details

No response

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions