FirstHack Learn
Log in Sign up free
Lessons in this course 0/6 All courses Secure Coding Practices

Cyber Security

Progress0 / 6 lessons
  1. 1. Never trust user input
  2. 2. SQL injection and parameterised queries
  3. 3. XSS and output encoding
  4. 4. Secrets management in code
  5. 5. Dependency and supply-chain hygiene
  6. 6. Logging and error handling without leaks

Courses › Secure Coding Practices

Dependency and supply-chain hygiene

Your code is 5% yours. How to know what the other 95% is doing.

12 min read · Lesson 5 of 6 · Pro

The size of the problem

Run pip install flask in a clean virtual environment. Flask arrives with Werkzeug, Jinja2, Click, itsdangerous, MarkupSafe and blinker. Add a database driver and a few utilities and a small project easily depends on forty packages written by dozens of people you have never met.

Every one of those packages runs with the same permissions as your code. A supply-chain attack does not break into your program. It gets invited.

This code prints what you actually have installed.

Python 3
from importlib.metadata import distributions
The rest of this lesson is Pro

The free lessons of Secure Coding Practices finish what they start — read those first if you have not. This one goes further, and it is part of the paid half.

A pass opens the paid lessons of every course, the mock test papers and the company-wise series. It ends on its own date; nothing renews by itself.

Get a pass — from ₹29 for 7 days

Already bought one? Log in.