Synapse
⌘+K
Synapse
PulseExploreClubsResearchersJournals
Instagram
HomeClubsExplore
August 1, 2026Journal of Software Evolution and ProcessOpen Access

Security Assessment of Private Package Repositories: An Experience on Acc‐Py at CERN

View Full Paper
Ask AI
Bookmark
Share

Authors

MLMichele LizzitFPFrancesco PinzautiMMMarino Miculan

Discussion

Loading...

Member takes

Overview

Compares security in private and public package repositories, revealing risks and strengths in Acc‐Py at CERN.

Key Points

  • Assess and compare the security of private package repositories and their public counterparts, focusing on Acc‐Py and PyPI.
  • Conduct a comprehensive security assessment of private and public repositories
  • Utilize open-source static analyzers for vulnerability detection
  • Engage in discussions with the CERN development team to gather insights
  • Acc‐Py shows fewer potential security issues compared to the PyPI ecosystem.
  • Acc‐Py is vulnerable to dependency confusion attacks due to namespace collisions with PyPI.
  • Dynamic analysis reveals telemetry collection presents privacy risks.

Cite This Study

Lizzit et al. (2026) studied this question.

synapsesocial.com/papers/6a6da778e258b358b3c6c901https://doi.org/10.1002/smr.70159
View Full Paper
Ask AI
Bookmark
Share