Dependency confusion¶
Birsan, A. (2021). Dependency confusion.
Retired. This entry was not a citation. Our extractor stored an inline prose definition from the article as though it were a bibliographic record: the title names a concept rather than a published work, and the citation text names no work at all. The page is kept because links to it still resolve, but it is withdrawn from the reference list. This entry is kept so the citations that pointed at it still resolve, and so the correction is visible rather than silent.
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Mechanisms¶
- Package Repository
- The classic misuse is trusting name resolution blindly, which opens the door to a dependency confusion attack, in which a malicious public package with an internal-sounding name is resolved in place of the private one it impersonates.
This sourceScoped namespaces and pinned, hash-verified lockfiles are the standard defenses, which is why namespace and resolution strategy are tuning dials above rather than afterthoughts.
- The classic misuse is trusting name resolution blindly, which opens the door to a dependency confusion attack, in which a malicious public package with an internal-sounding name is resolved in place of the private one it impersonates.
Verification¶
This reference passed the adversarial substantiation pipeline: it was checked to exist and to support the claim it is attached to. See how references were verified.
Registry ID ref:d618e8df764f · see in the full table