Watch
Russ Cox at ACM SCORED: Open Source Supply Chain Security at Google
Go's tech lead walks through real supply-chain attacks and how Go's design (checksum database, reproducible builds, no install-time code execution) defends against each.
Engineering Fundamentals for the Agent Era
An import of a package that does not exist, or of a lookalike name an attacker registered to catch exactly that mistake.
A large dependency added to replace ten lines of code.
Unpinned versions that pull in a compromised release on the next install.
Install scripts that run arbitrary code on every developer machine and build server.
Every package you install, and every package it pulls in, is code you run with your own permissions.
An agent's pull request adds three packages: one whose name is a single letter off a popular library, one that brings in 140 transitive dependencies to pad a string, and one with an install script that downloads a binary. Decide which to reject, and show how you would confirm that each package is the one you think it is.
Watch
Go's tech lead walks through real supply-chain attacks and how Go's design (checksum database, reproducible builds, no install-time code execution) defends against each.
Takes apart the event-stream compromise, where a new maintainer slipped a targeted payload into a transitive dependency, showing how an unpinned install pulls in malicious code.
Research on the ways developers are misled into importing the wrong package, typosquats and lookalike names among them, and how to detect confusable names.
Identifies the risks and controls at each link of the chain, from secure development to third-party risk and software transparency.
Explains SBOMs, attestations and provenance: what they record, how producers and consumers use them, and how they show what went into a release.
Its dependency-management chapter explains why every added dependency is a long-term cost and why version resolution is hard, which is the case for adding fewer packages.
Paper
The primary study measuring how often code models invent package names that do not exist, the basis for the 'slopsquatting' attack in this subsection's catches.
Specification
Defines build provenance and the levels of assurance it gives, so you can verify an artifact was built from the source and pipeline you expect.