Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
#
supplychainsecurity
Follow
Hide
Posts
Left menu
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
OpenAI open-sources the Codex Security CLI and keeps the scanner in-house
Leo
Leo
Leo
Follow
Jul 30
OpenAI open-sources the Codex Security CLI and keeps the scanner in-house
#
openai
#
codex
#
supplychainsecurity
#
codescanning
Comments
Add Comment
4 min read
Docker's fourth horror story revisits the Nx post-install hook that drained CI secrets
Leo
Leo
Leo
Follow
Jul 29
Docker's fourth horror story revisits the Nx post-install hook that drained CI secrets
#
supplychainsecurity
#
npm
#
postinstallhooks
#
cirunners
Comments
Add Comment
3 min read
GitHub Actions freezes suspected-malicious workflow runs until a human signs off
Leo
Leo
Leo
Follow
Jul 28
GitHub Actions freezes suspected-malicious workflow runs until a human signs off
#
githubactions
#
supplychainsecurity
#
workflowapproval
#
cicdsecurity
Comments
Add Comment
4 min read
Dependabot's 3-Day Cooldown: Why Waiting Is Now Safer
Induwara Ashinsana
Induwara Ashinsana
Induwara Ashinsana
Follow
Jul 24
Dependabot's 3-Day Cooldown: Why Waiting Is Now Safer
#
supplychainsecurity
#
dependabot
#
npm
Comments
Add Comment
4 min read
FakeGit floods GitHub with malicious repos aimed at coding agents
Leo
Leo
Leo
Follow
Jul 24
FakeGit floods GitHub with malicious repos aimed at coding agents
#
supplychainsecurity
#
codingagents
#
github
#
malware
Comments
Add Comment
2 min read
The npm worm that shipped with valid SLSA provenance
Leo
Leo
Leo
Follow
Jul 22
The npm worm that shipped with valid SLSA provenance
#
supplychainsecurity
#
slsa
#
provenance
#
npm
Comments
Add Comment
4 min read
The Codecov bash uploader is five years old, and the class of attack still lives in your pipeline
Leo
Leo
Leo
Follow
Jul 3
The Codecov bash uploader is five years old, and the class of attack still lives in your pipeline
#
supplychainsecurity
#
codecov
#
cisecrets
#
bashuploader
Comments
Add Comment
3 min read
Supply Chain Attacks verstehen: Praxisnahe Schutzstrategien fĂĽr moderne IT-Infrastrukturen
Uhltak Therestismysecret
Uhltak Therestismysecret
Uhltak Therestismysecret
Follow
Jul 2
Supply Chain Attacks verstehen: Praxisnahe Schutzstrategien fĂĽr moderne IT-Infrastrukturen
#
supplychainsecurity
#
softwaredependencies
#
cybersecurity
#
devsecops
Comments
Add Comment
6 min read
Perplexity Bumblebee Review: The Supply Chain Scanner Your Dev Machine Needs
Maksim Danilchenko
Maksim Danilchenko
Maksim Danilchenko
Follow
Jun 29
Perplexity Bumblebee Review: The Supply Chain Scanner Your Dev Machine Needs
#
bumblebee
#
perplexity
#
supplychainsecurity
#
go
Comments
Add Comment
11 min read
Design Trade-offs: Why Hermes (and Many Popular Agents) Don't Use LangChain / LangGraph
eyanpen
eyanpen
eyanpen
Follow
Jun 29
Design Trade-offs: Why Hermes (and Many Popular Agents) Don't Use LangChain / LangGraph
#
agentloop
#
langchain
#
langgraph
#
supplychainsecurity
Comments
Add Comment
8 min read
Building CIS-Hardened, SBOM-Attested CentOS 9 Golden Images with Packer, QEMU and PingAccess - entirely on WSL2
DarkEdges
DarkEdges
DarkEdges
Follow
Jun 28
Building CIS-Hardened, SBOM-Attested CentOS 9 Golden Images with Packer, QEMU and PingAccess - entirely on WSL2
#
devsecops
#
packer
#
supplychainsecurity
#
linux
Comments
Add Comment
6 min read
The Atomic Arch Supply Chain Attack: What 1,500 Compromised AUR Packages Mean for Cloud-Native CI/CD Security
The Cyber Sidekick
The Cyber Sidekick
The Cyber Sidekick
Follow
Jun 17
The Atomic Arch Supply Chain Attack: What 1,500 Compromised AUR Packages Mean for Cloud-Native CI/CD Security
#
supplychainsecurity
#
containersecurity
#
archlinux
#
sbom
Comments
Add Comment
4 min read
Miasma Worm: How Opening a Repo in Claude Code Became a Credential Theft Vector
Toni Antunovic
Toni Antunovic
Toni Antunovic
Follow
Jun 11
Miasma Worm: How Opening a Repo in Claude Code Became a Credential Theft Vector
#
security
#
supplychainsecurity
#
claudecode
#
devsecops
Comments
Add Comment
9 min read
The Gemini CLI CVSS 10 Attack: How a GitHub Issue Became a Supply Chain Weapon
Toni Antunovic
Toni Antunovic
Toni Antunovic
Follow
Jun 9
The Gemini CLI CVSS 10 Attack: How a GitHub Issue Became a Supply Chain Weapon
#
security
#
promptinjection
#
supplychainsecurity
#
devsecops
Comments
Add Comment
6 min read
Supply Chain Attacks: Schutz vor bösartigen Abhängigkeiten im IT-Betrieb
Uhltak Therestismysecret
Uhltak Therestismysecret
Uhltak Therestismysecret
Follow
Jun 4
Supply Chain Attacks: Schutz vor bösartigen Abhängigkeiten im IT-Betrieb
#
supplychainsecurity
#
abhaengigkeiten
#
devsecops
#
softwaresupplychain
Comments
Add Comment
5 min read
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account