2026-08-24

Mitigating Supply Chain Security Risks in Data Science

How Posit Package Manager layers curation, blocking, cooldowns, and unified repositories into a defensible open-source supply chain.
Mitigating supply chain security risks in data science whitepaper preview
Share

Data science runs on open-source packages — and so do the attackers targeting it. This updated whitepaper covers the threat landscape across PyPI, CRAN, Bioconductor, and the Open VSX extension registry, from typosquatting and dependency confusion to compromised maintainer accounts like the XZ Utils backdoor (CVE-2024-3094).

New in this edition: the Posit Package Service CDN architecture, package cooldown and minimum-age rules, VS Code extension governance, and expanded blocking by vulnerability, license, and custom criteria.