[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fLpc7pWT0yp2ndgQAADlUFOLCSzwgmf5xxwLlLzUBBKg":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":46},"e85290ff-067c-430e-92ae-e1b1956e5996","missing-lockfiles-open-the-door-to-supply-chain-attacks","498b3ae0-5499-4f8e-8dd1-dfaa7ecd160f","Missing Lockfiles Open the Door to Supply Chain Attacks","The absence of lockfiles in software projects means dependency resolution is non-deterministic, allowing malicious or compromised package versions to be silently introduced during installation. The Axios npm compromise illustrated this danger — without pinned dependency trees, the blast radius of a single compromised package can expand far beyond what developers initially expect. Projects relying on floating version ranges are effectively trusting that every upstream dependency remains uncompromised at every point in time, which is an unsafe assumption. Manifest Alerts from Socket surface this hidden risk by flagging projects where installs are not reproducible, giving teams actionable visibility before an attack occurs.","**Immediate actions:**\n- Audit all active repositories to identify projects missing lockfiles (e.g., package-lock.json, yarn.lock, poetry.lock) and generate them immediately.\n- Pin all direct and transitive dependencies to exact versions to ensure reproducible builds across all environments.\n\n**Long-term improvements:**\n- Integrate supply chain security tooling (e.g., Socket, Dependabot, or Snyk) into CI\u002FCD pipelines to automatically flag unpinned or suspicious dependencies on every pull request.\n- Establish and enforce an organizational policy requiring lockfiles as a mandatory artifact for all software projects before deployment.\n- Adopt a Software Bill of Materials (SBOM) practice to maintain a verified inventory of all third-party components used in production software.\n\n**Detection measures:**\n- Enable automated alerts for any changes to dependency manifests or lockfiles during code review to detect unexpected version drift.\n- Monitor package registries and threat intelligence feeds for newly reported compromises affecting packages in your dependency tree.",[12,13,14,15,16,17,18,19],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 16: Application Software Security","NIST SP 800-161r1: Cybersecurity Supply Chain Risk Management","NIST SSDF PW.4: Reuse Existing, Well-Secured Software","NIST SP 800-218 (SSDF) PS.3: Archive and Protect Each Software Release","SLSA Supply Chain Levels for Software Artifacts (Provenance Requirements)","OWASP A06:2021 – Vulnerable and Outdated Components","EO 14028: Improving the Nation's Cybersecurity (SBOM mandate)","published","2026-06-16T16:21:09.946152+00:00","2026-06-16T16:21:09.827+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fsocket.dev\u002Fblog\u002Fintroducing-manifest-alerts?utm_medium=feed","introducing-manifest-alerts-17162e","Introducing Manifest Alerts",[28,34,40],{"id":29,"name":30,"slug":31,"description":32,"color":33},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":35,"name":36,"slug":37,"description":38,"color":39},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":41,"name":42,"slug":43,"description":44,"color":45},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]