DEV Community

#supplychainsecurity

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
OpenAI open-sources the Codex Security CLI and keeps the scanner in-house

OpenAI open-sources the Codex Security CLI and keeps the scanner in-house

Comments
4 min read
Docker's fourth horror story revisits the Nx post-install hook that drained CI secrets

Docker's fourth horror story revisits the Nx post-install hook that drained CI secrets

Comments
3 min read
GitHub Actions freezes suspected-malicious workflow runs until a human signs off

GitHub Actions freezes suspected-malicious workflow runs until a human signs off

Comments
4 min read
Dependabot's 3-Day Cooldown: Why Waiting Is Now Safer

Dependabot's 3-Day Cooldown: Why Waiting Is Now Safer

Comments
4 min read
FakeGit floods GitHub with malicious repos aimed at coding agents

FakeGit floods GitHub with malicious repos aimed at coding agents

Comments
2 min read
The npm worm that shipped with valid SLSA provenance

The npm worm that shipped with valid SLSA provenance

Comments
4 min read
The Codecov bash uploader is five years old, and the class of attack still lives in your pipeline

The Codecov bash uploader is five years old, and the class of attack still lives in your pipeline

Comments
3 min read
Supply Chain Attacks verstehen: Praxisnahe Schutzstrategien fĂĽr moderne IT-Infrastrukturen

Supply Chain Attacks verstehen: Praxisnahe Schutzstrategien fĂĽr moderne IT-Infrastrukturen

Comments
6 min read
Perplexity Bumblebee Review: The Supply Chain Scanner Your Dev Machine Needs

Perplexity Bumblebee Review: The Supply Chain Scanner Your Dev Machine Needs

Comments
11 min read
Design Trade-offs: Why Hermes (and Many Popular Agents) Don't Use LangChain / LangGraph

Design Trade-offs: Why Hermes (and Many Popular Agents) Don't Use LangChain / LangGraph

Comments
8 min read
Building CIS-Hardened, SBOM-Attested CentOS 9 Golden Images with Packer, QEMU and PingAccess - entirely on WSL2

Building CIS-Hardened, SBOM-Attested CentOS 9 Golden Images with Packer, QEMU and PingAccess - entirely on WSL2

Comments
6 min read
The Atomic Arch Supply Chain Attack: What 1,500 Compromised AUR Packages Mean for Cloud-Native CI/CD Security

The Atomic Arch Supply Chain Attack: What 1,500 Compromised AUR Packages Mean for Cloud-Native CI/CD Security

Comments
4 min read
Miasma Worm: How Opening a Repo in Claude Code Became a Credential Theft Vector

Miasma Worm: How Opening a Repo in Claude Code Became a Credential Theft Vector

Comments
9 min read
The Gemini CLI CVSS 10 Attack: How a GitHub Issue Became a Supply Chain Weapon

The Gemini CLI CVSS 10 Attack: How a GitHub Issue Became a Supply Chain Weapon

Comments
6 min read
Supply Chain Attacks: Schutz vor bösartigen Abhängigkeiten im IT-Betrieb

Supply Chain Attacks: Schutz vor bösartigen Abhängigkeiten im IT-Betrieb

Comments
5 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.