Dependency Security Check
When to use
- Adding a new dependency to any project
- Running pip install, npm install, go get, or equivalent
- Auditing existing dependencies for supply-chain risk
- Reviewing a PR that adds or updates dependencies
- Investigating a potential supply-chain compromise
Skip when
- No dependencies are being added, updated, or audited
- Task involves only internal code changes with no new imports
- Dependency is already vetted and pinned in lockfile
Related
Complementary: ring:dev-docker-security, ring:dev-implementation
Supply-chain gate for every install command in a Lerian codebase.
Pre-Install Checks
1. Package Identity Verification
For every package, verify:
├── Typosquatting: compare against known popular packages
│ e.g., "requets" vs "requests", "rnodule" vs "module"
├── Homoglyph attacks: look-alike Unicode characters
├── Maintainer risk:
│ - Single maintainer = higher risk
│ - Account age < 6 months = flag
│ - Recent ownership transfer = CRITICAL flag
└── Package age: < 30 days = flag
2. Vulnerability Database Check
| Source |
Ecosystem |
What It Covers |
| OSV.dev |
All |
Google aggregated CVEs |
| GitHub Advisory Database |
All |
GHSA linked to CVEs |
| Socket.dev |
npm, pip |
Supply-chain: install scripts, network access |
| PyPI JSON API |
pip |
Metadata, maintainers, release history |
| npm registry API |
npm |
Metadata, maintainers, install scripts |
| Go vulnerability DB (vuln.go.dev) |
Go |
Official Go CVE database |
3. Behavioral Signals
| Signal |
Risk Level |
Description |
| Install scripts |
HIGH |
postinstall (npm), setup.py subprocess |
| Network access at import |
CRITICAL |
Package phones home on import |
| File system access outside project |
HIGH |
Reads ~/.ssh, ~/.aws, env vars |
| Obfuscated code |
CRITICAL |
Base64 payloads, eval(), exec() |
| Native binary bundled |
HIGH |
Pre-compiled binaries without source |
4. Lockfile Integrity
| Ecosystem |
Lockfile |
Hash Requirement |
| Go |
go.sum |
SHA-256 native — Go handles automatically |
| npm |
package-lock.json |
integrity field (SHA-512) must be present for ALL deps |
| pip |
requirements.txt |
--require-hashes MUST be enforced |
| Cargo |
Cargo.lock |
checksum field verification |
Risk Scoring
risk_score = weighted_sum(
typosquatting_similarity * 25,
maintainer_risk * 20,
package_age_risk * 15,
vulnerability_count * 20, # weighted by severity
behavioral_flags * 15,
lockfile_integrity * 5
)
Score thresholds:
- 0-25: LOW — proceed
- 26-50: MEDIUM — proceed with documentation
- 51-75: HIGH — escalate to Fred before installing
- 76-100: CRITICAL — block installation
Decision Matrix
| Risk Level |
Action |
| LOW (0-25) |
✅ Approve — document in PR |
| MEDIUM (26-50) |
⚠️ Conditional — mitigations required |
| HIGH (51-75) |
🚨 Escalate to Fred before installing |
| CRITICAL (76-100) |
❌ Block — do not install |
Report Template
## Dependency Security Report
Package: {name} @ {version}
Ecosystem: {go|npm|pip}
Risk Score: {score}/100 — {LOW|MEDIUM|HIGH|CRITICAL}
### Verification Results
| Check | Status | Details |
|-------|--------|---------|
| Typosquatting check | PASS/FLAG | {comparison} |
| Maintainer verification | PASS/FLAG | {maintainer count, age} |
| Vulnerability scan | PASS/FLAG | {CVE count, severity} |
| Behavioral analysis | PASS/FLAG | {signals found} |
| Lockfile integrity | PASS/FAIL | {hash present/missing} |
### Decision
{APPROVED|CONDITIONAL|ESCALATE|BLOCKED}
### Required Actions (if not APPROVED)
1. {specific mitigations or alternatives}
Mitigations for MEDIUM Risk
- Pin exact version in lockfile
- Vendor the dependency (copy source into repo)
- Document why this specific package was chosen over alternatives
- Add to security monitoring (e.g., GitHub Dependabot alerts)
1---2name: ring-dev-dep-security-check3description: Intercepts and audits dependency installations (pip, npm, go) before they execute. Validates package identity, checks vulnerabilities, flags supply-chain risk signals, and enforces hash pinning in lockfiles.4---5
6# Dependency Security Check
7
8## When to use
9- Adding a new dependency to any project
10- Running pip install, npm install, go get, or equivalent
11- Auditing existing dependencies for supply-chain risk
12- Reviewing a PR that adds or updates dependencies
13- Investigating a potential supply-chain compromise
14
15## Skip when
16- No dependencies are being added, updated, or audited
17- Task involves only internal code changes with no new imports
18- Dependency is already vetted and pinned in lockfile
19
20## Related
21**Complementary:** ring:dev-docker-security, ring:dev-implementation
22
23
24Supply-chain gate for every install command in a Lerian codebase.
25
26## Pre-Install Checks
27
28### 1. Package Identity Verification
29
30```
31For every package, verify:
32├── Typosquatting: compare against known popular packages
33│ e.g., "requets" vs "requests", "rnodule" vs "module"
34├── Homoglyph attacks: look-alike Unicode characters
35├── Maintainer risk:
36│ - Single maintainer = higher risk
37│ - Account age < 6 months = flag
38│ - Recent ownership transfer = CRITICAL flag
39└── Package age: < 30 days = flag
40```
41
42### 2. Vulnerability Database Check
43
44| Source | Ecosystem | What It Covers |
45|--------|-----------|----------------|
46| OSV.dev | All | Google aggregated CVEs |
47| GitHub Advisory Database | All | GHSA linked to CVEs |
48| Socket.dev | npm, pip | Supply-chain: install scripts, network access |
49| PyPI JSON API | pip | Metadata, maintainers, release history |
50| npm registry API | npm | Metadata, maintainers, install scripts |
51| Go vulnerability DB (vuln.go.dev) | Go | Official Go CVE database |
52
53### 3. Behavioral Signals
54
55| Signal | Risk Level | Description |
56|--------|-----------|-------------|
57| Install scripts | HIGH | `postinstall` (npm), `setup.py` subprocess |
58| Network access at import | CRITICAL | Package phones home on import |
59| File system access outside project | HIGH | Reads `~/.ssh`, `~/.aws`, env vars |
60| Obfuscated code | CRITICAL | Base64 payloads, eval(), exec() |
61| Native binary bundled | HIGH | Pre-compiled binaries without source |
62
63### 4. Lockfile Integrity
64
65| Ecosystem | Lockfile | Hash Requirement |
66|-----------|----------|-----------------|
67| Go | go.sum | SHA-256 native — Go handles automatically |
68| npm | package-lock.json | `integrity` field (SHA-512) must be present for ALL deps |
69| pip | requirements.txt | `--require-hashes` MUST be enforced |
70| Cargo | Cargo.lock | `checksum` field verification |
71
72## Risk Scoring
73
74```
75risk_score = weighted_sum(
76 typosquatting_similarity * 25,
77 maintainer_risk * 20,
78 package_age_risk * 15,
79 vulnerability_count * 20, # weighted by severity
80 behavioral_flags * 15,
81 lockfile_integrity * 5
82)
83```
84
85Score thresholds:
86- 0-25: LOW — proceed
87- 26-50: MEDIUM — proceed with documentation
88- 51-75: HIGH — escalate to Fred before installing
89- 76-100: CRITICAL — block installation
90
91## Decision Matrix
92
93| Risk Level | Action |
94|-----------|--------|
95| LOW (0-25) | ✅ Approve — document in PR |
96| MEDIUM (26-50) | ⚠️ Conditional — mitigations required |
97| HIGH (51-75) | 🚨 Escalate to Fred before installing |
98| CRITICAL (76-100) | ❌ Block — do not install |
99
100## Report Template
101
102```markdown
103## Dependency Security Report
104
105Package: {name} @ {version}
106Ecosystem: {go|npm|pip}
107Risk Score: {score}/100 — {LOW|MEDIUM|HIGH|CRITICAL}
108
109### Verification Results
110
111| Check | Status | Details |
112|-------|--------|---------|
113| Typosquatting check | PASS/FLAG | {comparison} |
114| Maintainer verification | PASS/FLAG | {maintainer count, age} |
115| Vulnerability scan | PASS/FLAG | {CVE count, severity} |
116| Behavioral analysis | PASS/FLAG | {signals found} |
117| Lockfile integrity | PASS/FAIL | {hash present/missing} |
118
119### Decision
120{APPROVED|CONDITIONAL|ESCALATE|BLOCKED}
121
122### Required Actions (if not APPROVED)
1231. {specific mitigations or alternatives}
124```
125
126## Mitigations for MEDIUM Risk
127
128- Pin exact version in lockfile
129- Vendor the dependency (copy source into repo)
130- Document why this specific package was chosen over alternatives
131- Add to security monitoring (e.g., GitHub Dependabot alerts)