The Changelog: Software Development, Open Source cover image

Securing the open source supply chain (Interview)

The Changelog: Software Development, Open Source

00:00

Navigating Typo Squatting in Software Packages

This chapter explores the management of typo squatting in package repositories, focusing on methodologies for identifying potential typos using metrics like Levenshtein distance and download statistics. It discusses the development of a new tool for monitoring dependencies, balancing user safety with the need to avoid overwhelming developers with alerts. The conversation also examines the importance of supply chain security in open source software, addressing complexities in license changes and risks associated with common packages.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app