Package Manager Threat Models

General News

Summary

This article examines threat models for package managers and the security weaknesses that affect modern software supply chains. It covers common attack paths such as typosquatting, dependency confusion, lockfile tampering, malicious install scripts, and repository or publisher account compromise. It also discusses protections like lockfiles, trusted publishing, 2FA, secret scanning, CI safeguards, and provenance attestations. The piece uses examples from ecosystems such as npm, PyPI, Cargo, RubyGems, Go, and Deno to show how supply chain risk crosses language boundaries.

Classifications

industries
Retail
applications
Audit

AskAI Classifications

Labels
Developer Tools Software Distribution SaaS

Linked Companies

Npmjs
$1M to $5M
Go
up to $1M