-
Notifications
You must be signed in to change notification settings - Fork 225
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
blog: Dependency Confusion and Typosquatting Attacks #1109
Conversation
…Attacks Blogpost that looks at dependency confusion and typosquatting attacks from defender's perspective and defines "managed ingestion" as an important capability for supply chain risk management. Signed-off-by: Meder Kydyraliev <1212257+meder@users.noreply.github.com>
✅ Deploy Preview for slsa ready!
To edit notification comments on pull requests, go to your Netlify site configuration. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Made a few minor suggestions for clarity, but otherwise this looks good to me. Thank you for writing this up.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM, I agree with @joshuagl 's suggestions.
Co-authored-by: Joshua Lock <joshuagloe@gmail.com> Signed-off-by: Meder Kydyraliev <1212257+meder@users.noreply.github.com>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for this blog post. A couple questions to help drive better clarity.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for submitting this blog post @meder ! My main high-level question is about the audience for this blog post. This is a relatively advanced topic, so if the intent is to reach a more general audience, my main suggestion is to make some revisions in the text that would help such an audience grapple with this topic. Either way, I left several comments that should help smooth out the flow and ease the transitions between sections to guide a more familiar reader as well.
Signed-off-by: Meder Kydyraliev <1212257+meder@users.noreply.github.com>
@arewm @marcelamelara thank you both for the review and feedback, PTAL. |
Signed-off-by: Meder Kydyraliev <1212257+meder@users.noreply.github.com>
Thank you for the clarifications, @marcelamelara. Feedback was addressed, PTAL. |
Co-authored-by: Marcela Melara <marcela.melara@intel.com> Signed-off-by: Meder Kydyraliev <1212257+meder@users.noreply.github.com>
Signed-off-by: Meder Kydyraliev <1212257+meder@users.noreply.github.com>
Signed-off-by: Meder Kydyraliev <1212257+meder@users.noreply.github.com>
@marcelamelara I believe all feedback was addressed, PTAL. |
@marcelamelara @arewm I'd like to target publish this on Wed (Sep 4th), please let me know if you have any blocking feedback. |
Signed-off-by: Meder Kydyraliev <1212257+meder@users.noreply.github.com>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for this blog post!
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for all of the updates @meder ! LGTM.
…1109) Blogpost that looks at dependency confusion and typosquatting attacks from defender's perspective and defines "managed ingestion" as an important capability for supply chain risk management. --------- Signed-off-by: Meder Kydyraliev <1212257+meder@users.noreply.github.com> Co-authored-by: Joshua Lock <joshuagloe@gmail.com> Co-authored-by: Marcela Melara <marcela.melara@intel.com>
Blogpost that looks at dependency confusion and typosquatting attacks from defender's perspective and defines "managed ingestion" as an important capability for supply chain risk management.