Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
#
supplychain
Follow
Hide
Posts
Left menu
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
uv audit vs pip-audit, and a gate narrower than it looks
curioustore
curioustore
curioustore
Follow
Jul 10
uv audit vs pip-audit, and a gate narrower than it looks
#
python
#
security
#
devops
#
supplychain
5
 reactions
Comments
Add Comment
13 min read
GhostApproval: six AI coding agents shipped a permission dialog that was reading the wrong path
Leo
Leo
Leo
Follow
Jul 10
GhostApproval: six AI coding agents shipped a permission dialog that was reading the wrong path
#
aiagents
#
codingagents
#
supplychain
#
security
Comments
Add Comment
4 min read
setup-java 5.5.0 adds JDK signature verification, if you remember to enable it
Leo
Leo
Leo
Follow
Jul 9
setup-java 5.5.0 adds JDK signature verification, if you remember to enable it
#
githubactions
#
java
#
signing
#
supplychain
Comments
Add Comment
3 min read
npm v12 flips install-time to closed-by-default
Leo
Leo
Leo
Follow
Jul 9
npm v12 flips install-time to closed-by-default
#
npm
#
supplychain
#
security
#
2fa
Comments
Add Comment
3 min read
PolinRider keeps expanding, and the postinstall still lands on your runner
Leo
Leo
Leo
Follow
Jul 8
PolinRider keeps expanding, and the postinstall still lands on your runner
#
supplychain
#
security
#
npm
#
maliciouspackages
Comments
Add Comment
3 min read
The SBOM you can trust is the one your build actually made
Leo
Leo
Leo
Follow
Jul 8
The SBOM you can trust is the one your build actually made
#
sbom
#
supplychain
#
docker
#
buildkit
Comments
Add Comment
4 min read
From vexctl scripts to a governed VEX platform: building vex-ui with Next.js, keyless signing, and a Trivy-consumable repo
DarkEdges
DarkEdges
DarkEdges
Follow
Jul 7
From vexctl scripts to a governed VEX platform: building vex-ui with Next.js, keyless signing, and a Trivy-consumable repo
#
security
#
nextjs
#
devops
#
supplychain
Comments
Add Comment
5 min read
MCP supply chain attacks are coming — here's how to prepare
Edison Flores
Edison Flores
Edison Flores
Follow
Jul 7
MCP supply chain attacks are coming — here's how to prepare
#
mcp
#
security
#
supplychain
#
npm
Comments
Add Comment
2 min read
GitHub starts watching the whole public site for your leaked secrets
Leo
Leo
Leo
Follow
Jul 6
GitHub starts watching the whole public site for your leaked secrets
#
github
#
secretscanning
#
supplychain
#
enterprise
Comments
Add Comment
4 min read
Cordyceps and the pipeline attack surface we keep ignoring
Leo
Leo
Leo
Follow
Jul 2
Cordyceps and the pipeline attack surface we keep ignoring
#
cicdsecurity
#
supplychain
#
runners
#
vulnerability
Comments
Add Comment
3 min read
Why MLCC Lead Times Are Blowing Up in 2026 (And How to Design Around It)
Lucas Ding
Lucas Ding
Lucas Ding
Follow
Jul 1
Why MLCC Lead Times Are Blowing Up in 2026 (And How to Design Around It)
#
electronics
#
hardware
#
pcb
#
supplychain
Comments
Add Comment
3 min read
Aikido buys Root to patch open source in place, without the upgrade dance
Leo
Leo
Leo
Follow
Jul 1
Aikido buys Root to patch open source in place, without the upgrade dance
#
supplychain
#
cve
#
dependencies
#
security
Comments
Add Comment
4 min read
The Supply Chain Attack Vector Everyone Is Ignoring in AI Agents
Poxek AI
Poxek AI
Poxek AI
Follow
Jun 30
The Supply Chain Attack Vector Everyone Is Ignoring in AI Agents
#
ai
#
programming
#
supplychain
#
attack
Comments
Add Comment
3 min read
GitHub Actions hands fork triggers a read-only cache token
Leo
Leo
Leo
Follow
Jun 30
GitHub Actions hands fork triggers a read-only cache token
#
githubactions
#
cache
#
supplychain
#
leastprivilege
Comments
Add Comment
4 min read
CI is the wrong place to first hear about your npm dependencies
Leo
Leo
Leo
Follow
Jun 29
CI is the wrong place to first hear about your npm dependencies
#
supplychain
#
shiftleft
#
node
#
npm
Comments
Add Comment
3 min read
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account