Reproducible Builds
Lock based source control systems
NPM 5
https://gitstashapply.medium.com/understanding-package-lock-json-024a0f32ef2f
Pip
https://www.freecodecamp.org/news/python-requirementstxt-explained/
https://medium.com/@sdboyer/so-you-want-to-write-a-package-manager-4ae9c17d9527
Example csproj
https://www.mend.io/blog/understanding-the-anatomy-of-a-malicious-package-attack/
Malicious Package Attack
Package version
consolidation
Unknown Transitive Dependencies
Versions managed globally vs locally
CLI experience vs GUI focused
Reproducible Builds
Compatible with existing Nuget ecosystem