DEV Community

# supplychain

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Bumblebee vs OSV-Scanner: Two Takes on Supply Chain Scanning

Bumblebee vs OSV-Scanner: Two Takes on Supply Chain Scanning

1
Comments
4 min read
npm Supply Chain Audit: The Checklist Most Teams Stop Too Early

npm Supply Chain Audit: The Checklist Most Teams Stop Too Early

Comments
6 min read
Four iteration rounds on a security scanner I run, all of them visible. Here is what the loop actually looks like.

Four iteration rounds on a security scanner I run, all of them visible. Here is what the loop actually looks like.

Comments
11 min read
FrontGate: a Lightweight Package Proxy for Supply Chain Security

FrontGate: a Lightweight Package Proxy for Supply Chain Security

Comments
2 min read
PCB Shortage Warning: Iran-Saudi Conflict Drives 40% Price Increase — What Hardware Engineers Need to Know

PCB Shortage Warning: Iran-Saudi Conflict Drives 40% Price Increase — What Hardware Engineers Need to Know

Comments
2 min read
Supply Chain Data Flow: Why Errors Happen in ERP Systems

Supply Chain Data Flow: Why Errors Happen in ERP Systems

Comments
7 min read
node-ipc Had a 69 Trust Score Before It Got Hacked. TanStack Had 91.

node-ipc Had a 69 Trust Score Before It Got Hacked. TanStack Had 91.

Comments
4 min read
GitHub No Fue Hackeado, Pero Tu Pipeline SĂ­ PodrĂ­a Serlo: Lo Que Revelan Grafana, CISA y Shai-Hulud 2.0

GitHub No Fue Hackeado, Pero Tu Pipeline SĂ­ PodrĂ­a Serlo: Lo Que Revelan Grafana, CISA y Shai-Hulud 2.0

Comments
7 min read
GitHub Wasn't Hacked, But Your CI/CD Pipeline Might Be: Lessons from Grafana, CISA, and Shai-Hulud 2.0

GitHub Wasn't Hacked, But Your CI/CD Pipeline Might Be: Lessons from Grafana, CISA, and Shai-Hulud 2.0

Comments
6 min read
The 4 Hidden Bottlenecks in the GLP-1 Supply Chain

The 4 Hidden Bottlenecks in the GLP-1 Supply Chain

Comments
3 min read
Software Supply Chain Security: SBOM, SLSA & Sigstore

Software Supply Chain Security: SBOM, SLSA & Sigstore

Comments
2 min read
Causa GitHub, or: Your Editor Extensions Run as You

Causa GitHub, or: Your Editor Extensions Run as You

Comments 1
5 min read
The TanStack Attack: How a Worm Slipped Through the npm Pipeline

The TanStack Attack: How a Worm Slipped Through the npm Pipeline

Comments
6 min read
The MCP package looked clean. The installed tree did not.

The MCP package looked clean. The installed tree did not.

1
Comments
2 min read
npm Is on Fire: Why the Architecture Is the Product

npm Is on Fire: Why the Architecture Is the Product

Comments
10 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.