5 ms·
To mitigate this kind of supply chain attacks for python, we have created following tool [1], that will check python packages on Artifactory instance you specif
by mbag 6y ago
To mitigate this kind of supply chain attacks for python, we have created following tool [1], that will check python packages on Artifactory instance you specify and create packages with the same name on the PyPi.
[1] https://github.com/pan-net-security/artifactory-pypi-scanner https://github.com/pan-net-security/artifactory-pypi-scanner
- seg_lol 6y agoThe thing that just happened is like a catastrophic chain-reaction collision in space. Now we will have to use guids for everything. Nothing has meaning.
- joshlk 6y agoUploading dummy packages to PyPi isn't the solution. It just pollutes PyPi and a nuisance to others. You have always been able to specify the `index-url` when installing packages using pip. This can also be added to `requirements.txt` files as well.
- matusf 6y agoSpecifying `index-url` is not a solution since `pip` will always choose a package with higher version regardless of the repository. Moreover, in case of same version, it will prioritize PyPI. This was discussed in following issues [0], [1]. [0]: https://github.com/pypa/pip/issues/5045 https://github.com/pypa/pip/issues/5045 [1]: https://github.com/pypa/pip/issues/8606 https://github.com/pypa/pip/issues/8606
- mbag 6y agoYes, if you have packages on the artifactory the `index-url` is always a way to go. However, if you forget to specify `no-index`, you might not get what you wanted, see [1] for how packages are found. And it's easy to make such mistake when using local resources (you forget to set proxy or internal DNS, new developer is not familiar with the setup and does plain `pip install`, internal server is temporarily unreachable). >It just pollutes PyPi and a nuisance to others. I agree, but so are the packages that are no longer maintained. You also reserve pakcage name if you decide to opensource it. Furthermore, by creating package you are leaking metadata about your organization, i.e. some functionality can be inferred from package names. And sure you can train and try to enforce security awareness, but your people need to be right 100% of the time, while attackers need them to make only one mistake. Similar with namesquatting of the popular packages. https://pip.pypa.io/en/stable/reference/pip_install/#finding-packages https://pip.pypa.io/en/stable/reference/pip_install/#finding...