Lockfiles improve repeatability, not eternal safety
A lockfile guarantees everybody builds the same thing. It does not guarantee the thing is good.
It freezes the versions you resolved on the day you resolved them, including the flaws they contained. Teams sometimes treat a lockfile as a security control, when it is a consistency control with a security side effect that cuts both ways.
More on Software supply chain
- A trusted build can faithfully ship malicious sourceThe oven never reads the recipe
- Dependency confusion exploits naming and resolutionSame name, wrong shelf
- Typosquatting attacks developer attentionThe eye test you take at 2am
- Transitive dependencies enlarge unseen trustOne handshake, a hundred guests
- Maintainer compromise can use the normal release channelIt came by the usual van
- Build secrets should not become build artefactsDeleted on top, still underneath
