drduh / drduh/macOS-Security-and-Privacy-Guide

Supply-chain risk section

Open
#544 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Shell
Stars
22.5k
Forks
1.5k
Avg merge
2d 2h
Merged PRs (30d)
5

Description

- create dedicated section for managing dependency/package-manager risk
- include Homebrew taps, casks, npm, Python, Ruby, Docker images, VS Code extensions
- explain pinning versions and verifying signatures/provenance
- explain risk of `curl | sh`, unmaintained packages, compromised developer accounts, typosquatting, etc.
- recommend review of installer packages and install scripts before running them

Contributor guide

No contributing guide indexed for this repository

Research direction

No file or test is named; start by reviewing the guide's existing structure and security sections to choose where a dedicated supply-chain risk section belongs. Add coverage for the listed package ecosystems and risks, including version pinning, signature or provenance checks, installer review, and the requested warnings.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, node.js, python, ruby, vscode
Domain
documentation, security
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.