<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Dependency-Management on CuraSec</title><link>https://curasec.metacog.co.kr/tags/dependency-management/</link><description>Recent content in Dependency-Management on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 14 Aug 2026 11:54:18 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/dependency-management/index.xml" rel="self" type="application/rss+xml"/><item><title>AI Coding Tools Outpace Package Vetting in Open Source Pipelines</title><link>https://curasec.metacog.co.kr/insights/2026-08-14-who-vets-ai-s-code-the-scale-challenge-facing-open-source-in/</link><pubDate>Fri, 14 Aug 2026 11:54:18 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-14-who-vets-ai-s-code-the-scale-challenge-facing-open-source-in/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> AI-hallucinated package names (slopsquatting) can silently introduce malicious or nonexistent dependencies before traditional review catches them; worth auditing whether your CI/CD enforces an approved-package allowlist before AI-generated code is merged, but no active exploitation signal here warrants immediate action.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>GitHub Adds 3-Day Dependabot Cooldown to Block Poisoned Package PRs</title><link>https://curasec.metacog.co.kr/insights/2026-07-27-github-adds-3-day-dependabot-cooldown-to-limit-poisoned-pack/</link><pubDate>Mon, 27 Jul 2026 13:44:31 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-27-github-adds-3-day-dependabot-cooldown-to-limit-poisoned-pack/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Review all repos using Dependabot and explicitly configure the cooldown parameter in dependabot.yml; the 3-day default delays auto-PR creation for fresh packages, reducing poisoned-package exposure in automated update pipelines.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Signals growing industry recognition of time-based supply chain defenses; useful context for maturing your software supply chain policy, though no immediate leadership action is required.&lt;/li>
&lt;/ul></description></item><item><title>GitHub and PyPI add time-based supply chain attack defenses</title><link>https://curasec.metacog.co.kr/insights/2026-07-27-github-pypi-add-time-based-defenses-against-supply-chain-att/</link><pubDate>Mon, 27 Jul 2026 13:44:31 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-27-github-pypi-add-time-based-defenses-against-supply-chain-att/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Review your Dependabot configuration and PyPI dependency pinning strategy to take advantage of the new time-based controls; evaluate whether enabling these features fits your dependency update workflow this quarter.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> GitHub and PyPI are hardening the open-source ecosystem against supply chain attacks — useful context for board-level supply chain risk discussions, but no immediate action required.&lt;/li>
&lt;/ul></description></item><item><title>AI Hallucinated Package Names Enable Supply-Chain Squatting Attacks</title><link>https://curasec.metacog.co.kr/insights/2026-07-25-slopsquatting-phantom-domains-and-hallusquatting-are-the-sam/</link><pubDate>Sat, 25 Jul 2026 12:08:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-25-slopsquatting-phantom-domains-and-hallusquatting-are-the-sam/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If your team uses AI coding assistants to generate dependency names or package imports, audit your pipeline for pre-fetch verification steps that confirm packages exist before installation; add a governed allowlist or lockfile discipline to block hallucinated names from resolving to malicious registries.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Understanding that AI agents can introduce malicious packages via hallucinated names expands the threat model for build-pipeline anomaly detection, but no IOCs or active campaign details are present to act on now.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> If your engineering teams use AI coding assistants, evaluate whether your software supply-chain policy requires dependency verification controls that cover AI-generated package references — this is a governance gap worth closing this quarter.&lt;/li>
&lt;/ul></description></item></channel></rss>