DFIELDSOLUTIONS

Security

GlossarySupply-chain attack

Attacking you through something you trust — a poisoned dependency, a compromised build tool — instead of attacking you directly.

Your code is perhaps 1% of what runs: the rest is dependencies, and their dependencies. An attacker who compromises one popular package reaches every project that installs it — which is why 'event-stream' and 'log4shell' are household names and why npm installs have a postinstall-scripts problem.

The defences are unglamorous inventory work: a dependency manifest (SBOM), version pinning with lockfiles, scanning in CI, and healthy suspicion of packages published yesterday with ten downloads. You cannot audit a thousand dependencies by hand; you can decide which thousand you run.

Related terms

The bench this belongs to

Cybersecurity

Purple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.

All termsStart a conversationMarkdown version

DField Bt. · Dunakeszi · dezso@dfieldsolutions.com
5.0
“From LinkedIn DM to live site. Two tiny tweaks, then shipped.”Michael J Ringer · Vilya ProtectionFounder · Spain