skip to content

Supply Chain Attack Vectors

You will learn the concrete ways attackers inject themselves between a developer and production — poisoned packages, hijacked maintainers, compromised build servers — anchored in the named incidents everyone cites. Interviewers open with these cases to test whether you understand the threat model before the tooling.

on this pageshow

explore

questions

page 2 of 2

Distros replaced an abandoned image library with a community fork under the same name. What breaks?

level: seniorimportance: nice to knowfreq 31%

basics

~10 s

Inventory stops identifying what you run. One name and version now cover two codebases, so advisories written against one lineage match the wrong code, producing irrelevant findings and missed ones.

open as a page

The board asks which supply chain entry points your pipeline is open to today — how do you answer with evidence?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Answer door by door rather than with a maturity score: for the build system, the maintainer, the delivery channel and the publishing account, state whether something enforces closure, what evidence proves it, and what closing the open ones would cost.

open as a page

Disabling install scripts fleet-wide breaks a third of your builds - is that switch a control?

level: principalimportance: nice to knowfreq 38%

basics

~20 s

On its own, no. The flag removes one execution point without deciding which packages you trust, and it holds only where someone set it. Import-time code still runs. A control has an owner, an enforcement point, an exception path and evidence.

open as a page

Across an estate of single-owner internal services, code review is a rubber stamp. What do you change?

level: principalimportance: nice to knowfreq 31%

basics

~20 s

Stop treating the approval as review. Rank services by what their code can reach, buy genuine reviewer capacity only for that short list, and replace review elsewhere with detective controls and narrower runtime authority — then correct the compliance claim.

open as a page

showing 31–34 of 34