Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
#
supplychain
Follow
Hide
Posts
Left menu
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
Bumblebee vs OSV-Scanner: Two Takes on Supply Chain Scanning
Alan West
Alan West
Alan West
Follow
May 24
Bumblebee vs OSV-Scanner: Two Takes on Supply Chain Scanning
#
security
#
supplychain
#
devops
#
npm
1
 reaction
Comments
Add Comment
4 min read
npm Supply Chain Audit: The Checklist Most Teams Stop Too Early
Pico
Pico
Pico
Follow
May 22
npm Supply Chain Audit: The Checklist Most Teams Stop Too Early
#
npm
#
security
#
javascript
#
supplychain
Comments
Add Comment
6 min read
Four iteration rounds on a security scanner I run, all of them visible. Here is what the loop actually looks like.
Michael Kayode Onyekwere
Michael Kayode Onyekwere
Michael Kayode Onyekwere
Follow
May 21
Four iteration rounds on a security scanner I run, all of them visible. Here is what the loop actually looks like.
#
security
#
supplychain
#
mcp
#
npm
Comments
Add Comment
11 min read
FrontGate: a Lightweight Package Proxy for Supply Chain Security
Max Kryvych
Max Kryvych
Max Kryvych
Follow
May 21
FrontGate: a Lightweight Package Proxy for Supply Chain Security
#
supplychain
#
governance
#
security
#
ai
Comments
Add Comment
2 min read
PCB Shortage Warning: Iran-Saudi Conflict Drives 40% Price Increase — What Hardware Engineers Need to Know
AtlasPCBEngineering
AtlasPCBEngineering
AtlasPCBEngineering
Follow
May 21
PCB Shortage Warning: Iran-Saudi Conflict Drives 40% Price Increase — What Hardware Engineers Need to Know
#
hardware
#
electronics
#
supplychain
#
manufacturing
Comments
Add Comment
2 min read
Supply Chain Data Flow: Why Errors Happen in ERP Systems
Mustafa ERBAY
Mustafa ERBAY
Mustafa ERBAY
Follow
May 20
Supply Chain Data Flow: Why Errors Happen in ERP Systems
#
tutorials
#
erp
#
supplychain
#
dataflow
Comments
Add Comment
7 min read
node-ipc Had a 69 Trust Score Before It Got Hacked. TanStack Had 91.
Pico
Pico
Pico
Follow
May 20
node-ipc Had a 69 Trust Score Before It Got Hacked. TanStack Had 91.
#
npm
#
security
#
supplychain
#
javascript
Comments
Add Comment
4 min read
GitHub No Fue Hackeado, Pero Tu Pipeline SĂ PodrĂa Serlo: Lo Que Revelan Grafana, CISA y Shai-Hulud 2.0
jesus manrique
jesus manrique
jesus manrique
Follow
May 19
GitHub No Fue Hackeado, Pero Tu Pipeline SĂ PodrĂa Serlo: Lo Que Revelan Grafana, CISA y Shai-Hulud 2.0
#
cybersecurity
#
github
#
devops
#
supplychain
Comments
Add Comment
7 min read
GitHub Wasn't Hacked, But Your CI/CD Pipeline Might Be: Lessons from Grafana, CISA, and Shai-Hulud 2.0
jesus manrique
jesus manrique
jesus manrique
Follow
May 19
GitHub Wasn't Hacked, But Your CI/CD Pipeline Might Be: Lessons from Grafana, CISA, and Shai-Hulud 2.0
#
cybersecurity
#
github
#
devops
#
supplychain
Comments
Add Comment
6 min read
The 4 Hidden Bottlenecks in the GLP-1 Supply Chain
Harry Floyd
Harry Floyd
Harry Floyd
Follow
May 18
The 4 Hidden Bottlenecks in the GLP-1 Supply Chain
#
biotech
#
pharma
#
supplychain
#
analysis
Comments
Add Comment
3 min read
Software Supply Chain Security: SBOM, SLSA & Sigstore
InstaDevOps
InstaDevOps
InstaDevOps
Follow
May 17
Software Supply Chain Security: SBOM, SLSA & Sigstore
#
security
#
supplychain
#
sbom
#
devops
Comments
Add Comment
2 min read
Causa GitHub, or: Your Editor Extensions Run as You
Vivian Voss
Vivian Voss
Vivian Voss
Follow
May 21
Causa GitHub, or: Your Editor Extensions Run as You
#
security
#
supplychain
#
vscode
#
devsecops
Comments
1
 comment
5 min read
The TanStack Attack: How a Worm Slipped Through the npm Pipeline
jesus manrique
jesus manrique
jesus manrique
Follow
May 15
The TanStack Attack: How a Worm Slipped Through the npm Pipeline
#
security
#
devsecops
#
npm
#
supplychain
Comments
Add Comment
6 min read
The MCP package looked clean. The installed tree did not.
Bindfort
Bindfort
Bindfort
Follow
May 15
The MCP package looked clean. The installed tree did not.
#
security
#
ai
#
mcp
#
supplychain
1
 reaction
Comments
Add Comment
2 min read
npm Is on Fire: Why the Architecture Is the Product
Vivian Voss
Vivian Voss
Vivian Voss
Follow
May 14
npm Is on Fire: Why the Architecture Is the Product
#
npm
#
supplychain
#
security
#
freebsd
Comments
Add Comment
10 min read
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account