Transitive dependencies enlarge unseen trust
You chose ten libraries. You are running four hundred.
Everything you depend on brings its own dependencies, several levels deep, and almost nobody looks past the first. Those indirect packages have the same access to your process as the ones you selected deliberately. The gap between what teams believe they run and what they actually run is usually an order of magnitude.
More on Software supply chain
- A trusted build can faithfully ship malicious sourceThe oven never reads the recipe
- Dependency confusion exploits naming and resolutionSame name, wrong shelf
- Typosquatting attacks developer attentionThe eye test you take at 2am
- Lockfiles improve repeatability, not eternal safetyAlways the same tin
- Maintainer compromise can use the normal release channelIt came by the usual van
- Build secrets should not become build artefactsDeleted on top, still underneath
