Software Supply Chain Security
The Jungle and Software Supply Chain Security
Unsparing observations on dependencies, provenance, and questionable packages
After reading it, you will never again run an install script from a blog post without a moment of class consciousness.
Sinclair tours the modern dependency ecosystem with the calm horror it deserves. This book covers lockfiles, signed artefacts, vulnerability scanning, transitive risk, and the practical business of knowing what, precisely, has been installed in production.
Contents
- The Packing House of Transitive Dependencies
- Lockfiles and Other Modest Protections
- A Bill of Materials for the Appalled
- Signing the Artefact Before It Escapes
Published by Austenpunk, the distinguished imprint for engineers who believe that every production incident would be improved by a stronger sense of narrative irony.
This essential volume combines literary feeling, technical anxiety, and just enough documentation to suggest that somebody once understood the system.