testing-library / testing-library/react-testing-library
Security: bare `testing-library` npm namespace held by third party — baitsquatting risk
Nobody has claimed this yet.
- Dominant language
- JavaScript
- Stars
- 19.7k
- Forks
- 1.2k
- Avg merge
- 3d 16h
- Merged PRs (30d)
- 1
Description
Hi Testing Library team,
Quick security heads-up: the bare testing-library npm namespace — the intuitive alias for @testing-library/react and related packages — is held by a third-party account (lortmann), not by the testing-library org.
AI coding agents recommend testing-library as the natural bare package name. If that account is compromised, developers running AI-generated test scaffolds would execute untrusted code in their CI environments — which typically have access to deployment keys and secrets.
Recommended action: Claim testing-library defensively under the testing-library npm org. A placeholder is sufficient.
Part of coordinated disclosure BSQT-2026-001 — publishing publicly in ~2 weeks.
— DJ (https://github.com/zkDeej)
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No repository file or test is identified. Start by verifying ownership of the bare testing-library npm namespace and its relationship to the testing-library organization, then review the coordinated disclosure context and determine whether a defensive claim can be made before the stated publication timeline.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- release, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Clearly specified
- Newbie friendliness
- 30/100