diff --git a/src/content/supply-chain-security/upstream-trust.mdx b/src/content/supply-chain-security/upstream-trust.mdx index f4481508..eaf95fe8 100644 --- a/src/content/supply-chain-security/upstream-trust.mdx +++ b/src/content/supply-chain-security/upstream-trust.mdx @@ -3,7 +3,7 @@ import configure_upstream_trust from './images/configure_upstream_trust.png' import edit_upstream_trust from './images/edit_upstream_trust.png' # Upstream Trust -Upstream trust is a supply chain security feature that prevents namesquatting attacks where bad actors hijack your internal package name in public repositories. By designating upstream sources as trusted or untrusted, you control which sources are permitted to serve versions of packages that exist in your private repository or other trusted sources. +Upstream trust is a supply chain security feature that prevents dependency confusion or namesquatting attacks where bad actors hijack your internal package name in public repositories. By designating upstream sources as trusted or untrusted, you control which sources are permitted to serve versions of packages that exist in your private repository or other trusted sources. This is particularly important for organizations that publish private packages alongside public open-source dependencies. Without upstream trust, a malicious actor could publish a package with the same name as your private package to a public registry, potentially tricking your build systems into pulling the attacker's version instead of your own.