# Securing Node.js applications from supply-chain and other common security issues

**URL:** <https://discourse.nodered.org/t/securing-node-js-applications-from-supply-chain-and-other-common-security-issues/90871>\
**Category:** FAQs\
**Tags:** security\
**Created:** [10 September 2024 20:37 UTC](https://discourse.nodered.org/t/securing-node-js-applications-from-supply-chain-and-other-common-security-issues/90871 "2024-09-10T20:37:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [10 September 2024 20:37 UTC](https://discourse.nodered.org/t/securing-node-js-applications-from-supply-chain-and-other-common-security-issues/90871/1 "2024-09-10T20:37:46Z")

</div>

Node-RED is built on Node.js which has a number of potential security weaknesses if they are not mitigated properly. This article from the well-respected Auth0 team (now part of the Okta Identity and access management group) covers the common issues and offers thoughts on how to mitigate them.

> **[Secure Node.js Applications from Supply Chain Attacks](https://auth0.com/blog/secure-nodejs-applications-from-supply-chain-attacks/)**
>
> Guidelines and security best practices to protect from third-party threats

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [10 September 2024 21:08 UTC](https://discourse.nodered.org/t/securing-node-js-applications-from-supply-chain-and-other-common-security-issues/90871/2 "2024-09-10T21:08:59Z")

</div>

Is there much in there that affects us lesser mortals? Apart from the obvious ones to not run node-red as root, and to have a specific user for node-red with only the permissions that are needed.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [10 September 2024 23:12 UTC](https://discourse.nodered.org/t/securing-node-js-applications-from-supply-chain-and-other-common-security-issues/90871/3 "2024-09-10T23:12:23Z")

</div>

Much of it is for developers. For example, I'd already taken to using some of the supply-chain protection features available as GitHub actions for UIBUILDER. They protect from misbehaving or hijacked dependencies or vulnerabilities.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [10 October 2024 20:38 UTC](https://discourse.nodered.org/t/securing-node-js-applications-from-supply-chain-and-other-common-security-issues/90871/4 "2024-10-10T20:38:22Z")

</div>

This topic was automatically closed after 30 days. New replies are no longer allowed.
