DEV Community

#supplychainsecurity

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
CISA rewrites the SBOM floor: hashes are required, and the scope now covers AI and SaaS

CISA rewrites the SBOM floor: hashes are required, and the scope now covers AI and SaaS

Comments
3 min read
npm walls off 2FA-bypass tokens from account and package management

npm walls off 2FA-bypass tokens from account and package management

Comments
3 min read
Supply Chain Attacks verstehen: Praktische Tipps zur Abwehr von 2026

Supply Chain Attacks verstehen: Praktische Tipps zur Abwehr von 2026

Comments
6 min read
GTIG and Mandiant publish a supply-chain hardening playbook aimed at CI/CD teams

GTIG and Mandiant publish a supply-chain hardening playbook aimed at CI/CD teams

Comments
4 min read
OpenAI open-sources the Codex Security CLI and keeps the scanner in-house

OpenAI open-sources the Codex Security CLI and keeps the scanner in-house

Comments
4 min read
Docker's fourth horror story revisits the Nx post-install hook that drained CI secrets

Docker's fourth horror story revisits the Nx post-install hook that drained CI secrets

Comments
3 min read
GitHub Actions freezes suspected-malicious workflow runs until a human signs off

GitHub Actions freezes suspected-malicious workflow runs until a human signs off

Comments
4 min read
Dependabot's 3-Day Cooldown: Why Waiting Is Now Safer

Dependabot's 3-Day Cooldown: Why Waiting Is Now Safer

Comments
4 min read
FakeGit floods GitHub with malicious repos aimed at coding agents

FakeGit floods GitHub with malicious repos aimed at coding agents

Comments
2 min read
The npm worm that shipped with valid SLSA provenance

The npm worm that shipped with valid SLSA provenance

Comments
4 min read
The Codecov bash uploader is five years old, and the class of attack still lives in your pipeline

The Codecov bash uploader is five years old, and the class of attack still lives in your pipeline

Comments
3 min read
Supply Chain Attacks verstehen: Praxisnahe Schutzstrategien fĂĽr moderne IT-Infrastrukturen

Supply Chain Attacks verstehen: Praxisnahe Schutzstrategien fĂĽr moderne IT-Infrastrukturen

Comments
6 min read
Perplexity Bumblebee Review: The Supply Chain Scanner Your Dev Machine Needs

Perplexity Bumblebee Review: The Supply Chain Scanner Your Dev Machine Needs

Comments
11 min read
Design Trade-offs: Why Hermes (and Many Popular Agents) Don't Use LangChain / LangGraph

Design Trade-offs: Why Hermes (and Many Popular Agents) Don't Use LangChain / LangGraph

Comments
8 min read
Building CIS-Hardened, SBOM-Attested CentOS 9 Golden Images with Packer, QEMU and PingAccess - entirely on WSL2

Building CIS-Hardened, SBOM-Attested CentOS 9 Golden Images with Packer, QEMU and PingAccess - entirely on WSL2

Comments
6 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.