drduh / drduh/macOS-Security-and-Privacy-Guide
Supply-chain risk section
- Dominant language
- Shell
- Stars
- 22.5k
- Forks
- 1.5k
- Avg merge
- 2d 2h
- Merged PRs (30d)
- 5
Description
- create dedicated section for managing dependency/package-manager risk
- include Homebrew taps, casks, npm, Python, Ruby, Docker images, VS Code extensions
- explain pinning versions and verifying signatures/provenance
- explain risk of `curl | sh`, unmaintained packages, compromised developer accounts, typosquatting, etc.
- recommend review of installer packages and install scripts before running them
Contributor guide
No contributing guide indexed for this repository
Research direction
No file or test is named; start by reviewing the guide's existing structure and security sections to choose where a dedicated supply-chain risk section belongs. Add coverage for the listed package ecosystems and risks, including version pinning, signature or provenance checks, installer review, and the requested warnings.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker, node.js, python, ruby, vscode
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 55/100