Q: Your security team discovers that the Python package `requests` used in your build was silently replaced in PyPI with a malicious version via a "dependency confusion" attack. No one noticed for 2 weeks because the version number was valid. How do you architect your CI pipeline to prevent this class of attack permanently?
This is a dependency confusion or typosquatting supply chain attack. Three layers of defence are required:
#CI/CD #๐ Supply Chain Security & Advanced CI/CD #L3 #DevOps #Automation #Pipelines
๐๏ธ Candidate Opening & Architectural Context
""In our delivery pipeline supporting multiple engineering squads, pipeline reliability was paramount. The interviewer is testing: Dependency integrity verification, private package mirrors, hash pinning.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
๐ ๏ธ Production Runbook & Step-by-Step Resolution
1๏ธโฃ
Initial Diagnostics & Root Cause Analysis
This is a dependency confusion or typosquatting supply chain attack. Three layers of defence are required:
- Hash Pinning: Use
pip install --require-hashes -r requirements.txt. Each package entry inrequirements.txtcontains its expectedsha256hash. If the file downloaded from PyPI doesn't match the exact hash, pip aborts the build immediately. - Private Mirror / Allowlist: Configure your CI to pull packages exclusively from an internal Artifactory or AWS CodeArtifact repository, not directly from the public internet. Every package entering that mirror is scanned and approved by the security team once.
- SBOM + CVE Scanning: Generate a Software Bill of Materials (SBOM) via
syfton every build and scan it withgrype. Any package that wasn't in the SBOM last build triggers an alert requiring human review.
2๏ธโฃ
Remediation & Permanent Safeguards
๐ก The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Hash Pinning: Use pip install --require-hashes -r requirements.txt. Each package entry in requirements.txt contains its expected s."
โก 60-Second Elevator Pitch Talking Points
- Hash Pinning: Use pip install --require-hashes -r requirements.txt. Each package entry in require...
- Private Mirror / Allowlist: Configure your CI to pull packages exclusively from an internal Artif...
- SBOM + CVE Scanning: Generate a Software Bill of Materials (SBOM) via syft on every build and sca...
Advertisement