Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
#
supplychainsecurity
Follow
Hide
Posts
Left menu
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
CISA rewrites the SBOM floor: hashes are required, and the scope now covers AI and SaaS
Leo
Leo
Leo
Follow
Aug 2
CISA rewrites the SBOM floor: hashes are required, and the scope now covers AI and SaaS
#
sbom
#
cisa
#
supplychainsecurity
#
provenance
Comments
Add Comment
3 min read
npm walls off 2FA-bypass tokens from account and package management
Leo
Leo
Leo
Follow
Aug 1
npm walls off 2FA-bypass tokens from account and package management
#
npm
#
supplychainsecurity
#
2fa
#
accesstokens
Comments
Add Comment
3 min read
Supply Chain Attacks verstehen: Praktische Tipps zur Abwehr von 2026
Uhltak Therestismysecret
Uhltak Therestismysecret
Uhltak Therestismysecret
Follow
Jul 30
Supply Chain Attacks verstehen: Praktische Tipps zur Abwehr von 2026
#
supplychainsecurity
#
supplychainattacks
#
softwaredependencies
#
devsecops
Comments
Add Comment
6 min read
GTIG and Mandiant publish a supply-chain hardening playbook aimed at CI/CD teams
Leo
Leo
Leo
Follow
Jul 30
GTIG and Mandiant publish a supply-chain hardening playbook aimed at CI/CD teams
#
supplychainsecurity
#
gtig
#
mandiant
#
cicdsecurity
Comments
Add Comment
4 min read
OpenAI open-sources the Codex Security CLI and keeps the scanner in-house
Leo
Leo
Leo
Follow
Jul 30
OpenAI open-sources the Codex Security CLI and keeps the scanner in-house
#
openai
#
codex
#
supplychainsecurity
#
codescanning
Comments
Add Comment
4 min read
Docker's fourth horror story revisits the Nx post-install hook that drained CI secrets
Leo
Leo
Leo
Follow
Jul 29
Docker's fourth horror story revisits the Nx post-install hook that drained CI secrets
#
supplychainsecurity
#
npm
#
postinstallhooks
#
cirunners
Comments
Add Comment
3 min read
GitHub Actions freezes suspected-malicious workflow runs until a human signs off
Leo
Leo
Leo
Follow
Jul 28
GitHub Actions freezes suspected-malicious workflow runs until a human signs off
#
githubactions
#
supplychainsecurity
#
workflowapproval
#
cicdsecurity
Comments
Add Comment
4 min read
Dependabot's 3-Day Cooldown: Why Waiting Is Now Safer
Induwara Ashinsana
Induwara Ashinsana
Induwara Ashinsana
Follow
Jul 24
Dependabot's 3-Day Cooldown: Why Waiting Is Now Safer
#
supplychainsecurity
#
dependabot
#
npm
Comments
Add Comment
4 min read
FakeGit floods GitHub with malicious repos aimed at coding agents
Leo
Leo
Leo
Follow
Jul 24
FakeGit floods GitHub with malicious repos aimed at coding agents
#
supplychainsecurity
#
codingagents
#
github
#
malware
Comments
Add Comment
2 min read
The npm worm that shipped with valid SLSA provenance
Leo
Leo
Leo
Follow
Jul 22
The npm worm that shipped with valid SLSA provenance
#
supplychainsecurity
#
slsa
#
provenance
#
npm
Comments
Add Comment
4 min read
The Codecov bash uploader is five years old, and the class of attack still lives in your pipeline
Leo
Leo
Leo
Follow
Jul 3
The Codecov bash uploader is five years old, and the class of attack still lives in your pipeline
#
supplychainsecurity
#
codecov
#
cisecrets
#
bashuploader
Comments
Add Comment
3 min read
Supply Chain Attacks verstehen: Praxisnahe Schutzstrategien fĂĽr moderne IT-Infrastrukturen
Uhltak Therestismysecret
Uhltak Therestismysecret
Uhltak Therestismysecret
Follow
Jul 2
Supply Chain Attacks verstehen: Praxisnahe Schutzstrategien fĂĽr moderne IT-Infrastrukturen
#
supplychainsecurity
#
softwaredependencies
#
cybersecurity
#
devsecops
Comments
Add Comment
6 min read
Perplexity Bumblebee Review: The Supply Chain Scanner Your Dev Machine Needs
Maksim Danilchenko
Maksim Danilchenko
Maksim Danilchenko
Follow
Jun 29
Perplexity Bumblebee Review: The Supply Chain Scanner Your Dev Machine Needs
#
bumblebee
#
perplexity
#
supplychainsecurity
#
go
Comments
Add Comment
11 min read
Design Trade-offs: Why Hermes (and Many Popular Agents) Don't Use LangChain / LangGraph
eyanpen
eyanpen
eyanpen
Follow
Jun 29
Design Trade-offs: Why Hermes (and Many Popular Agents) Don't Use LangChain / LangGraph
#
agentloop
#
langchain
#
langgraph
#
supplychainsecurity
Comments
Add Comment
8 min read
Building CIS-Hardened, SBOM-Attested CentOS 9 Golden Images with Packer, QEMU and PingAccess - entirely on WSL2
DarkEdges
DarkEdges
DarkEdges
Follow
Jun 28
Building CIS-Hardened, SBOM-Attested CentOS 9 Golden Images with Packer, QEMU and PingAccess - entirely on WSL2
#
devsecops
#
packer
#
supplychainsecurity
#
linux
Comments
Add Comment
6 min read
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account