Your Dependencies Are Part of Your Attack Surface
Sep 2026 · 1 min read
A typical web project pulls in hundreds of packages, most of them written by people you have never met. Each is code you run with your own permissions.
What goes wrong
Compromised maintainer accounts, malicious look-alike package names, and old vulnerabilities in packages nobody updates. Recent years have shown these are not rare edge cases.
Cheap defenses
- Commit your lockfile and install from it in CI.
- Turn on automated dependency alerts and update regularly, in small steps.
- Prefer fewer, well-maintained dependencies over many tiny ones.
- Review what a new package does before adding it, especially install scripts.
Go one step further
Generate a software bill of materials so you know what is in your builds. Use least-privilege tokens in CI, and keep secrets out of repositories.
The mindset
You cannot audit everything. Aim to reduce what you trust, make updates routine, and be able to answer quickly when a vulnerability is announced: are we affected?