...
Purpose:
The purpose of this investigation investigation to understand ONAP's current security posture regarding dependency management. If found to be lacking, recommendations will be made to enhance.
Notes from Samuli
The novel types of dependency confusion attacks utilize the way some package managers work (by default). In this case, “A dependency confusion attack or supply chain substitution attack occurs when a software installer script is tricked into pulling a malicious code file from a public repository instead of the intended file of the same name from an internal repository”. Quote from dependency confusion attacks, I recommend you read that very short article.
...