testing-library / testing-library/react-testing-library

Security: bare `testing-library` npm namespace held by third party — baitsquatting risk

Open
#1,459 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
JavaScript
Stars
19.7k
Forks
1.2k
Avg merge
3d 16h
Merged PRs (30d)
1

Description

Hi Testing Library team,

Quick security heads-up: the bare testing-library npm namespace — the intuitive alias for @testing-library/react and related packages — is held by a third-party account (lortmann), not by the testing-library org.

AI coding agents recommend testing-library as the natural bare package name. If that account is compromised, developers running AI-generated test scaffolds would execute untrusted code in their CI environments — which typically have access to deployment keys and secrets.

Recommended action: Claim testing-library defensively under the testing-library npm org. A placeholder is sufficient.

Part of coordinated disclosure BSQT-2026-001 — publishing publicly in ~2 weeks.

— DJ (https://github.com/zkDeej)

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No repository file or test is identified. Start by verifying ownership of the bare testing-library npm namespace and its relationship to the testing-library organization, then review the coordinated disclosure context and determine whether a defensive claim can be made before the stated publication timeline.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
release, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Clearly specified
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.