← all writing

Your Dependencies Are Part of Your Attack Surface

Sep 2026 · 1 min read

A typical web project pulls in hundreds of packages, most of them written by people you have never met. Each is code you run with your own permissions.

What goes wrong

Compromised maintainer accounts, malicious look-alike package names, and old vulnerabilities in packages nobody updates. Recent years have shown these are not rare edge cases.

Cheap defenses

  • Commit your lockfile and install from it in CI.
  • Turn on automated dependency alerts and update regularly, in small steps.
  • Prefer fewer, well-maintained dependencies over many tiny ones.
  • Review what a new package does before adding it, especially install scripts.

Go one step further

Generate a software bill of materials so you know what is in your builds. Use least-privilege tokens in CI, and keep secrets out of repositories.

The mindset

You cannot audit everything. Aim to reduce what you trust, make updates routine, and be able to answer quickly when a vulnerability is announced: are we affected?

Chat on WhatsApp