Skip to content

Archive

Dependencies

5 articles
Software Engineering 11 Sep 2026 9 min read

Stable Dependencies Principle: Point Toward Stability

Stable Dependencies Principle: Point Toward Stability A dependency graph is not only a map of which component calls which other component. Its direction also determines which parts of a system can change independently. Consider a reporting component used by ten other components. Many callers depend on it, so changing its public contract can require coordinated work across the codebase. That reporting component has become relatively stable: not necessarily because its code rarely changes, but because many other components constrain how freely its contract can change.

Cybersecurity 05 Sep 2026 8 min read

Prevent Dependency Confusion with Explicit Package Sources

A dependency declaration can look precise and still leave an important security question unanswered: where is this package allowed to come from? This matters when an organisation uses both private packages and a public package registry. If a package manager or build configuration can resolve the same package name from more than one source, an attacker may be able to publish a public package that competes with the intended private one. A build that selects the wrong source can then run attacker-controlled package code inside a trusted development or build environment.

Software Engineering 05 Sep 2026 8 min read

Isolating Volatile Dependencies Behind Stable Boundaries

A dependency can be technically easy to call and still be expensive to change. A pricing library may rename operations between releases. A shipping provider may expose a model that changes as its API evolves. An internal rules engine may be rewritten while the business workflow around it stays largely the same. When application code uses those changing details everywhere, each dependency change becomes an application-wide edit. The problem is not simply that the dependency changes. The problem is that knowledge of how it works today has spread into code that has different reasons to change.

Software Engineering 03 Sep 2026 10 min read

Directing Dependencies Toward Stable Code

A dependency can look harmless when it is introduced. A business rule calls a payment SDK directly, a reporting module knows the exact storage format, or an order workflow imports a concrete notification client. Each choice may save a small amount of code today. The cost appears later. When an external library, storage mechanism, or delivery channel changes, code that represents important business behaviour must change with it. Dependency direction is a way to reduce that coupling. The central idea is simple: code that expresses important, relatively stable policy should not have to know the details that are likely to change around it.

Cybersecurity 01 Sep 2026 4 min read

Reduce Software Supply Chain Risk with Dependency Controls

Modern applications routinely execute code downloaded from package registries, container registries, build actions, and language-specific ecosystems. That convenience creates supply chain risk: an attacker does not need to compromise your source repository if they can compromise something your build trusts. No single control eliminates this risk. The practical approach is to reduce unnecessary trust and make dependency changes visible. Treat dependency resolution as a security boundary A manifest may specify broad version ranges, while a lockfile records the exact dependency graph selected for a build.