Software Engineering KB

Home

❯

08 Security

❯

04 Supply Chain Security

❯

01 Concept

❯

Dependency Confusion

Dependency Confusion

Feb 10, 20261 min read

  • supply-chain-security
  • dependency-confusion

Dependency Confusion

← Back to Software Supply Chain

An attack where a private package name is registered on a public registry with a higher version number. Package managers that check public registries first may install the attacker’s version instead of the internal one. Mitigated by scoped registries and namespace reservation.

Key Properties

  • Public vs Private Registry Priority
  • Scoped Registries
  • Namespace Reservation

supply-chain-security dependency-confusion


Graph View

  • Dependency Confusion
  • Key Properties

Backlinks

  • Software Supply Chain

Created with Quartz v4.5.2 © 2026

  • GitHub