Package Manager Threat Models
Summary
This article examines threat models for package managers and the security weaknesses that affect modern software supply chains. It covers common attack paths such as typosquatting, dependency confusion, lockfile tampering, malicious install scripts, and repository or publisher account compromise. It also discusses protections like lockfiles, trusted publishing, 2FA, secret scanning, CI safeguards, and provenance attestations. The piece uses examples from ecosystems such as npm, PyPI, Cargo, RubyGems, Go, and Deno to show how supply chain risk crosses language boundaries.
Classifications
industries
Retail
applications
Audit
AskAI Classifications
Labels
Developer Tools
Software Distribution
SaaS