Security: bare `testing-library` npm namespace held by third party — baitsquatting risk
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 30/100
- Issue type
- Feature
- Clarity
- Clearly specified
- Activity status
- Quiet
- Tech stack
- javascript
Research direction
No repository file or test is identified. Start by verifying ownership of the bare testing-library npm namespace and its relationship to the testing-library organization, then review the coordinated disclosure context and determine whether a defensive claim can be made before the stated publication timeline.
Written by the indexing model from the issue text.
Description
Hi Testing Library team,
Quick security heads-up: the bare testing-library npm namespace — the intuitive alias for @testing-library/react and related packages — is held by a third-party account (lortmann), not by the testing-library org.
AI coding agents recommend testing-library as the natural bare package name. If that account is compromised, developers running AI-generated test scaffolds would execute untrusted code in their CI environments — which typically have access to deployment keys and secrets.
Recommended action: Claim testing-library defensively under the testing-library npm org. A placeholder is sufficient.
Part of coordinated disclosure BSQT-2026-001 — publishing publicly in ~2 weeks.
— DJ (https://github.com/zkDeej)
- Dominant language
- JavaScript
- Stars
- 19.7k
- Forks
- 1.2k
- PR merge metrics
- No merged PRs in 30d
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from testing-library/react-testing-library
-
fireEvent.select does not wrap its automatic native focus in actPossibly taken @sergioperezcheco claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 35/100
testing-library/react-testing-library#1466 · 1 comment ·
-
Difficulty 1/5 Under an hour Newbie friendliness 35/100
testing-library/react-testing-library#1430 · 1 comment ·
-
`fireEvent.mouseEnter` does not forward `relatedTarget` (relatedTarget is the window instead)Possibly taken @swarnim02 claimed this 314 days ago. Open
Difficulty 3/5 1-2 days Newbie friendliness 55/100
-
Difficulty 4/5 3-5 days Newbie friendliness 42/100
testing-library/react-testing-library#1421 · 1 comment ·
All issues in testing-library/react-testing-library
Similar issues
-
enhancement
Difficulty 1/5 Under an hour Newbie friendliness 90/100
-
app bug config windows-os
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
openai/codex#51926 · 2 comments ·
Maintainers usually reply within 1 day
-
clawsweeper:needs-product-decision clawsweeper:needs-security-review clawsweeper:no-new-fix-pr clawsweeper:source-repro impact:security issue-rating: 🦞 diamond lobster P2
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
openclaw/openclaw#166870 · 2 comments · 1 reaction ·
Maintainers usually reply within 1 day
-
⚠ needs intervention document structure changed
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
-
[Package] Widget primitives [Type] Enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
WordPress/gutenberg#84204 · 1 comment ·
Maintainers usually reply within 1 day