The introduction of package managers had a huge impact on software development, as they facilitate dependency management and the access to reusable code components. However, reliance on centralized repositories introduces security risks, as they are increasingly exploited in supply chain attacks. To reduce these risks, many companies rely on private package managers and repositories. Although public package repositories have been extensively studied, private ones remain underexplored. This paper presents a security comparison of private package repositories versus their public counterparts, through our experience on PyPI and CERN's Acc-Py. We perform a comprehensive security assessment of both repositories, complemented by discussions with the CERN development team. Using open-source static analyzers, we find that Acc-Py hosts packages with fewer potential security issues than those on the broad PyPI ecosystem. However, it remains susceptible to dependency confusion attacks due to namespace collisions with PyPI. Our dynamic analysis technique identifies telemetry collection as a privacy-monitoring trade-off. Our study provides valuable insights for analyzing and strengthening the security of private repositories, addressing their unique security challenges and attack surfaces.
Security Assessment of Private Package Repositories: An Experience on Acc-Py at CERN
Lizzit M.
;Miculan M.;Riccio V.
2026-01-01
Abstract
The introduction of package managers had a huge impact on software development, as they facilitate dependency management and the access to reusable code components. However, reliance on centralized repositories introduces security risks, as they are increasingly exploited in supply chain attacks. To reduce these risks, many companies rely on private package managers and repositories. Although public package repositories have been extensively studied, private ones remain underexplored. This paper presents a security comparison of private package repositories versus their public counterparts, through our experience on PyPI and CERN's Acc-Py. We perform a comprehensive security assessment of both repositories, complemented by discussions with the CERN development team. Using open-source static analyzers, we find that Acc-Py hosts packages with fewer potential security issues than those on the broad PyPI ecosystem. However, it remains susceptible to dependency confusion attacks due to namespace collisions with PyPI. Our dynamic analysis technique identifies telemetry collection as a privacy-monitoring trade-off. Our study provides valuable insights for analyzing and strengthening the security of private repositories, addressing their unique security challenges and attack surfaces.| File | Dimensione | Formato | |
|---|---|---|---|
|
J Software Evolu Process - 2026 - Lizzit - Security Assessment of Private Package Repositories An Experience on Acc‐Py at.pdf
accesso aperto
Tipologia:
Versione Editoriale (PDF)
Licenza:
Creative commons
Dimensione
1.26 MB
Formato
Adobe PDF
|
1.26 MB | Adobe PDF | Visualizza/Apri |
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.


