DEV Community

#supplychain

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
The Ghost in the Machine: Unraveling Persistent Git Compromises Beyond Your Control

The Ghost in the Machine: Unraveling Persistent Git Compromises Beyond Your Control

Comments
5 min read
The Artifactory Token Chain: Why Build Repositories Are a Credential Store

The Artifactory Token Chain: Why Build Repositories Are a Credential Store

Comments
4 min read
700 Agents, 25 Actions Each, and Nothing Fired

700 Agents, 25 Actions Each, and Nothing Fired

Comments
3 min read
The Artifact Repository Is a Trust Root: Reading the JFrog Artifactory Authentication Bypass

The Artifact Repository Is a Trust Root: Reading the JFrog Artifactory Authentication Bypass

Comments
4 min read
The Shai-Hulud npm worm showed that opening a folder is enough to run code

The Shai-Hulud npm worm showed that opening a folder is enough to run code

Comments
3 min read
Print Servers and Artifact Repositories: Measuring Two Overlooked Attack Surfaces

Print Servers and Artifact Repositories: Measuring Two Overlooked Attack Surfaces

Comments
3 min read
One Console, Every Customer: What the N-able N-central Pre-Authentication RCE Says About RMM Concentration Risk

One Console, Every Customer: What the N-able N-central Pre-Authentication RCE Says About RMM Concentration Risk

Comments
3 min read
The Default Join Key That Let Attackers Mint Admin Tokens on JFrog Artifactory

The Default Join Key That Let Attackers Mint Admin Tokens on JFrog Artifactory

Comments
4 min read
From Warehouses to Algorithms: How JD Logistics Builds a Technology-Driven Supply Chain

From Warehouses to Algorithms: How JD Logistics Builds a Technology-Driven Supply Chain

Comments
7 min read
Your coding agent installed 23 packages in a minute. Your SBOM saw zero.

Your coding agent installed 23 packages in a minute. Your SBOM saw zero.

Comments
3 min read
Your Coding Agent Reads the Repository Before You Do: Configuration Injection in AI Developer Tooling

Your Coding Agent Reads the Repository Before You Do: Configuration Injection in AI Developer Tooling

Comments
3 min read
Two encrypted emails in twenty years

Two encrypted emails in twenty years

Comments
5 min read
Artifactory on the Internet: Measuring the Exposure Behind CVE-2026-82329

Artifactory on the Internet: Measuring the Exposure Behind CVE-2026-82329

Comments
4 min read
Jenkins Controller Compromise Is a Supply Chain Event: Lessons from 20 Plugin Flaws

Jenkins Controller Compromise Is a Supply Chain Event: Lessons from 20 Plugin Flaws

Comments
4 min read
Self-Hosted CI Runners Are Shared Secrets: Threat Modelling Your Build Infrastructure

Self-Hosted CI Runners Are Shared Secrets: Threat Modelling Your Build Infrastructure

Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.