DEV Community

#supplychain

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
The 72-hour dependency cooldown is security theater that breaks your builds

The 72-hour dependency cooldown is security theater that breaks your builds

2
Comments 2
3 min read
npm provenance attestations get worn as camouflage in a new worm-style attack

npm provenance attestations get worn as camouflage in a new worm-style attack

Comments
5 min read
A shared agent-plugin format is a shared supply chain

A shared agent-plugin format is a shared supply chain

Comments 1
3 min read
Your Coding Agent Has a Supply Chain, and You Probably Have Not Scoped It

Your Coding Agent Has a Supply Chain, and You Probably Have Not Scoped It

Comments
8 min read
RapidFort points its hardened open-source business at what actually runs in production

RapidFort points its hardened open-source business at what actually runs in production

1
Comments
2 min read
CodeQL 2.26.2 trims what counts as safe: fresh alerts incoming

CodeQL 2.26.2 trims what counts as safe: fresh alerts incoming

1
Comments
3 min read
The Streak Continues: Four More Supply Chain Attacks Hit npm and PyPI

The Streak Continues: Four More Supply Chain Attacks Hit npm and PyPI

Comments
7 min read
Stop Slopsquatting With a CI Gate, Not a Better Prompt

Stop Slopsquatting With a CI Gate, Not a Better Prompt

Comments
4 min read
Image verification, one layer below admission

Image verification, one layer below admission

Comments
2 min read
PyPI stops accepting late file uploads to releases older than 14 days

PyPI stops accepting late file uploads to releases older than 14 days

Comments
3 min read
Agentic Supply Chain Vulnerabilities: Your Agent Is Only as Secure as Its Weakest Plugin (ASI04)

Agentic Supply Chain Vulnerabilities: Your Agent Is Only as Secure as Its Weakest Plugin (ASI04)

1
Comments
10 min read
xAI publishes Grok Build's source after the coding agent was caught siphoning SSH keys

xAI publishes Grok Build's source after the coding agent was caught siphoning SSH keys

Comments
3 min read
Mini Shai-Hulud: the tj-actions memory-dump script, reused fourteen months later

Mini Shai-Hulud: the tj-actions memory-dump script, reused fourteen months later

Comments
2 min read
The workstation is in scope now

The workstation is in scope now

Comments
3 min read
Clinejection: How a GitHub Issue Title Compromised an AI Coding Assistant Used by 5M Developers

Clinejection: How a GitHub Issue Title Compromised an AI Coding Assistant Used by 5M Developers

Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.