Building Software

Engineering Fundamentals for the Agent Era

Contents Section 8, Security

Dependencies and the Supply Chain

Mistakes to catch in review

  1. An import of a package that does not exist, or of a lookalike name an attacker registered to catch exactly that mistake.

  2. A large dependency added to replace ten lines of code.

  3. Unpinned versions that pull in a compromised release on the next install.

  4. Install scripts that run arbitrary code on every developer machine and build server.

Every package you install, and every package it pulls in, is code you run with your own permissions.

Topics

Choosing Dependencies
Checking maintenance, ownership, license and size before adding a package, and preferring fewer packages overall.
Pinning and Lockfiles
Making installs reproducible and updates deliberate.
Vulnerability Scanning and Patching
Finding known vulnerabilities in dependencies and updating them on a steady schedule.
Hallucinated and Typosquatted Packages
Package names that models invent and attackers register, and how to verify a package is the real one.
Provenance and SBOMs
Build attestations, signatures and software bills of materials that show what went into a release.

You understand it when you can

  • Evaluate a dependency's maintenance, ownership and security history before adding it.
  • Explain what a lockfile guarantees and what it does not.
  • Explain how to find every dependency a project ships, direct and transitive, and why the transitive ones need the same scrutiny.

Drill

An agent's pull request adds three packages: one whose name is a single letter off a popular library, one that brings in 140 transitive dependencies to pad a string, and one with an install script that downloads a binary. Decide which to reject, and show how you would confirm that each package is the one you think it is.

Start here

Watch

Read

Software Supply Chain Security: Securing the End-to-End Supply Chain for Software, Firmware, and Hardware

Cassie Crossley, 2024.

Identifies the risks and controls at each link of the chain, from secure development to third-party risk and software transparency.

Software Transparency: Supply Chain Security in an Era of a Software-Driven Society

Chris Hughes and Tony Turner, 2023.

Explains SBOMs, attestations and provenance: what they record, how producers and consumers use them, and how they show what went into a release.

Primary sources