Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
#
supplychain
Follow
Hide
Posts
Left menu
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
The Streak Continues: Four More Supply Chain Attacks Hit npm and PyPI
Dwayne McDaniel
Dwayne McDaniel
Dwayne McDaniel
Follow
for
GitGuardian
Jul 31
The Streak Continues: Four More Supply Chain Attacks Hit npm and PyPI
#
security
#
supplychain
#
npm
#
python
Comments
Add Comment
7 min read
Stop Slopsquatting With a CI Gate, Not a Better Prompt
jaryn
jaryn
jaryn
Follow
Jul 31
Stop Slopsquatting With a CI Gate, Not a Better Prompt
#
security
#
ai
#
supplychain
#
devsecops
Comments
Add Comment
4 min read
Image verification, one layer below admission
Leo
Leo
Leo
Follow
Jul 31
Image verification, one layer below admission
#
kubernetes
#
supplychain
#
policy
#
attestations
Comments
Add Comment
2 min read
PyPI stops accepting late file uploads to releases older than 14 days
Leo
Leo
Leo
Follow
Jul 28
PyPI stops accepting late file uploads to releases older than 14 days
#
supplychain
#
pypi
#
python
#
dependabot
Comments
Add Comment
3 min read
Agentic Supply Chain Vulnerabilities: Your Agent Is Only as Secure as Its Weakest Plugin (ASI04)
Maish Saidel-Keesing
Maish Saidel-Keesing
Maish Saidel-Keesing
Follow
for
AWS
Jul 21
Agentic Supply Chain Vulnerabilities: Your Agent Is Only as Secure as Its Weakest Plugin (ASI04)
#
aws
#
security
#
supplychain
#
ai
1
 reaction
Comments
Add Comment
10 min read
xAI publishes Grok Build's source after the coding agent was caught siphoning SSH keys
Leo
Leo
Leo
Follow
Jul 21
xAI publishes Grok Build's source after the coding agent was caught siphoning SSH keys
#
codingagents
#
supplychain
#
security
#
sshkeys
Comments
Add Comment
3 min read
Mini Shai-Hulud: the tj-actions memory-dump script, reused fourteen months later
Eldor Zufarov
Eldor Zufarov
Eldor Zufarov
Follow
Jul 20
Mini Shai-Hulud: the tj-actions memory-dump script, reused fourteen months later
#
devsecops
#
security
#
supplychain
#
cicd
Comments
Add Comment
2 min read
The workstation is in scope now
Leo
Leo
Leo
Follow
Jul 19
The workstation is in scope now
#
supplychain
#
developerworkstation
#
githubactions
#
vscode
Comments
Add Comment
3 min read
Clinejection: How a GitHub Issue Title Compromised an AI Coding Assistant Used by 5M Developers
Eldor Zufarov
Eldor Zufarov
Eldor Zufarov
Follow
Jul 19
Clinejection: How a GitHub Issue Title Compromised an AI Coding Assistant Used by 5M Developers
#
appsec
#
supplychain
#
devsecops
#
ai
Comments
Add Comment
3 min read
GitLab tries to auto-fix the transitive-dep problem it keeps quantifying
Leo
Leo
Leo
Follow
Jul 17
GitLab tries to auto-fix the transitive-dep problem it keeps quantifying
#
gitlab
#
supplychain
#
dependencies
#
autoremediation
Comments
Add Comment
5 min read
Cordyceps: when a stranger's pull request runs as a maintainer
Leo
Leo
Leo
Follow
Jul 16
Cordyceps: when a stranger's pull request runs as a maintainer
#
supplychain
#
githubactions
#
workflowsecurity
#
pullrequesttarget
Comments
Add Comment
3 min read
Crunchyroll Hackeada: 100GB Robados vĂa un Empleado de Telus
Diego Diaz
Diego Diaz
Diego Diaz
Follow
Jul 16
Crunchyroll Hackeada: 100GB Robados vĂa un Empleado de Telus
#
breach
#
supplychain
#
streaming
#
sony
Comments
Add Comment
5 min read
Inside the Chain: the tj-actions compromise wasn't one incident — it was three
Eldor Zufarov
Eldor Zufarov
Eldor Zufarov
Follow
Jul 16
Inside the Chain: the tj-actions compromise wasn't one incident — it was three
#
devsecops
#
security
#
supplychain
#
cicd
Comments
Add Comment
2 min read
Booking.com Breach: When the Vendor Chain Becomes the Attack Surface
Diego Diaz
Diego Diaz
Diego Diaz
Follow
Jul 16
Booking.com Breach: When the Vendor Chain Becomes the Attack Surface
#
breach
#
booking
#
vendorchain
#
supplychain
1
 reaction
Comments
Add Comment
2 min read
Dependabot learns to wait: version-update PRs now sit for three days by default
Leo
Leo
Leo
Follow
Jul 15
Dependabot learns to wait: version-update PRs now sit for three days by default
#
dependabot
#
github
#
supplychain
#
packageupdates
Comments
Add Comment
4 min read
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account