The introduction of package managers had a huge impact on software development, as they facilitate dependency management and the access to reusable code components. However, reliance on centralized repositories introduces security risks, as they are increasingly exploited in supply chain attacks. To reduce these risks, many companies rely on private package managers and repositories. Although public package repositories have been extensively studied, private ones remain underexplored. This paper presents a security comparison of private package repositories versus their public counterparts, through our experience on PyPI and CERN's Acc-Py. We perform a comprehensive security assessment of both repositories, complemented by discussions with the CERN development team. Using open-source static analyzers, we find that Acc-Py hosts packages with fewer potential security issues than those on the broad PyPI ecosystem. However, it remains susceptible to dependency confusion attacks due to namespace collisions with PyPI. Our dynamic analysis technique identifies telemetry collection as a privacy-monitoring trade-off. Our study provides valuable insights for analyzing and strengthening the security of private repositories, addressing their unique security challenges and attack surfaces.

Security Assessment of Private Package Repositories: An Experience on Acc-Py at CERN

Lizzit M.
;
Miculan M.;Riccio V.
2026-01-01

Abstract

The introduction of package managers had a huge impact on software development, as they facilitate dependency management and the access to reusable code components. However, reliance on centralized repositories introduces security risks, as they are increasingly exploited in supply chain attacks. To reduce these risks, many companies rely on private package managers and repositories. Although public package repositories have been extensively studied, private ones remain underexplored. This paper presents a security comparison of private package repositories versus their public counterparts, through our experience on PyPI and CERN's Acc-Py. We perform a comprehensive security assessment of both repositories, complemented by discussions with the CERN development team. Using open-source static analyzers, we find that Acc-Py hosts packages with fewer potential security issues than those on the broad PyPI ecosystem. However, it remains susceptible to dependency confusion attacks due to namespace collisions with PyPI. Our dynamic analysis technique identifies telemetry collection as a privacy-monitoring trade-off. Our study provides valuable insights for analyzing and strengthening the security of private repositories, addressing their unique security challenges and attack surfaces.
File in questo prodotto:
File Dimensione Formato  
J Software Evolu Process - 2026 - Lizzit - Security Assessment of Private Package Repositories An Experience on Acc‐Py at.pdf

accesso aperto

Tipologia: Versione Editoriale (PDF)
Licenza: Creative commons
Dimensione 1.26 MB
Formato Adobe PDF
1.26 MB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11390/1337987
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? 0
social impact