โšก ~/naveed Interview Prep
โšก Portfolio Home โœ๏ธ Engineering Blog Deep Dives ๐ŸŽฏ Interview Hub 998+ Scenarios โ˜ธ๏ธ Kubernetes Mastery Hub 24 Modules ๐ŸŽฎ DevOps Arcade & Quizzes Subnet Blitz โšก ๐Ÿ—บ๏ธ DevOps Roadmaps PDFs & Guides ๐Ÿค– Morpheus Analysis AI Quant โ†— ๐Ÿ› ๏ธ Developer Tools Utilities ๐Ÿงช Labs & Experiments ๐Ÿ“„ Interactive CV & Certs ๐Ÿ”— All Links & Socials โšก Join The Dispatch (Weekly SRE Newsletter) →
Staff SRE / Principal Architect [L3] CI/CD ๐Ÿ” Supply Chain Security & Advanced CI/CD Staff SRE Scenario [L3]

Q: Your security team discovers that the Python package `requests` used in your build was silently replaced in PyPI with a malicious version via a "dependency confusion" attack. No one noticed for 2 weeks because the version number was valid. How do you architect your CI pipeline to prevent this class of attack permanently?

This is a dependency confusion or typosquatting supply chain attack. Three layers of defence are required:

#CI/CD #๐Ÿ” Supply Chain Security & Advanced CI/CD #L3 #DevOps #Automation #Pipelines
๐ŸŽ™๏ธ Candidate Opening & Architectural Context
""In our delivery pipeline supporting multiple engineering squads, pipeline reliability was paramount. The interviewer is testing: Dependency integrity verification, private package mirrors, hash pinning.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement

๐Ÿ› ๏ธ Production Runbook & Step-by-Step Resolution

1๏ธโƒฃ

Initial Diagnostics & Root Cause Analysis

This is a dependency confusion or typosquatting supply chain attack. Three layers of defence are required:

  • Hash Pinning: Use pip install --require-hashes -r requirements.txt. Each package entry in requirements.txt contains its expected sha256 hash. If the file downloaded from PyPI doesn't match the exact hash, pip aborts the build immediately.
  • Private Mirror / Allowlist: Configure your CI to pull packages exclusively from an internal Artifactory or AWS CodeArtifact repository, not directly from the public internet. Every package entering that mirror is scanned and approved by the security team once.
  • SBOM + CVE Scanning: Generate a Software Bill of Materials (SBOM) via syft on every build and scan it with grype. Any package that wasn't in the SBOM last build triggers an alert requiring human review.
2๏ธโƒฃ

Remediation & Permanent Safeguards

๐Ÿ’ก The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Hash Pinning: Use pip install --require-hashes -r requirements.txt. Each package entry in requirements.txt contains its expected s."
โšก 60-Second Elevator Pitch Talking Points
  • Hash Pinning: Use pip install --require-hashes -r requirements.txt. Each package entry in require...
  • Private Mirror / Allowlist: Configure your CI to pull packages exclusively from an internal Artif...
  • SBOM + CVE Scanning: Generate a Software Bill of Materials (SBOM) via syft on every build and sca...
Advertisement
Want more CI/CD scenarios?
Explore our complete collection of scenario-based CI/CD interview runbooks.
Browse All CI/CD Questions →

๐Ÿ“š Related Production Scenarios in CI/CD