Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
#
supplychainsecurity
Follow
Hide
Posts
Left menu
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
RubyGems Supply Chain Vulnerability: What the OpenAI Bot Incident Teaches About Node.js and npm Security
Aditya Rawas
Aditya Rawas
Aditya Rawas
Follow
Sep 15
RubyGems Supply Chain Vulnerability: What the OpenAI Bot Incident Teaches About Node.js and npm Security
#
supplychainsecurity
#
npmvulnerabilities
#
packagemanagersecurity
#
rubygemscachingbug
Comments
Add Comment
7 min read
Supply Chain Security 2026: SBOM, Sigstore/SLSA, and Admission Control as DevOps Standard
saaro
saaro
saaro
Follow
Sep 13
Supply Chain Security 2026: SBOM, Sigstore/SLSA, and Admission Control as DevOps Standard
#
devops
#
supplychainsecurity
#
sigstore
#
slsa
Comments
Add Comment
4 min read
Software Artifact Trust Starts At Package Registries
Marcus Morris
Marcus Morris
Marcus Morris
Follow
Sep 16
Software Artifact Trust Starts At Package Registries
#
supplychainsecurity
#
opensource
#
appsec
#
python
Comments
Add Comment
2 min read
No CVE Is Coming for Android-Image-Cropper. Audit Anyway.
Jason Miller
Jason Miller
Jason Miller
Follow
Sep 5
No CVE Is Coming for Android-Image-Cropper. Audit Anyway.
#
android
#
supplychainsecurity
#
sca
#
dependencyaudit
Comments
Add Comment
3 min read
Container Image Signing & SLSA Provenance Verification with Sigstore Cosign
Aomi Qaza
Aomi Qaza
Aomi Qaza
Follow
Aug 15
Container Image Signing & SLSA Provenance Verification with Sigstore Cosign
#
supplychainsecurity
#
devops
Comments
Add Comment
4 min read
The LiteLLM compromise is not in any of the places you would look for it
Imran Siddique
Imran Siddique
Imran Siddique
Follow
Aug 14
The LiteLLM compromise is not in any of the places you would look for it
#
supplychainsecurity
#
cicd
#
security
#
devops
Comments
Add Comment
4 min read
CNCF's shadow-AI post makes the case for treating agents as identities
Leo
Leo
Leo
Follow
Aug 9
CNCF's shadow-AI post makes the case for treating agents as identities
#
shadowai
#
supplychainsecurity
#
cncf
#
kubernetes
Comments
Add Comment
3 min read
Omdia's 2026 supply-chain survey puts the annual-incident rate at 77 percent
Leo
Leo
Leo
Follow
Aug 4
Omdia's 2026 supply-chain survey puts the annual-incident rate at 77 percent
#
supplychainsecurity
#
sbom
#
containers
#
cicdsecurity
1
 reaction
Comments
Add Comment
2 min read
CISA's new OSS guidance puts a four-letter scoreboard next to every dependency you ship
Leo
Leo
Leo
Follow
Aug 3
CISA's new OSS guidance puts a four-letter scoreboard next to every dependency you ship
#
cisa
#
supplychainsecurity
#
opensource
#
dependencies
Comments
1
 comment
3 min read
CISA rewrites the SBOM floor: hashes are required, and the scope now covers AI and SaaS
Leo
Leo
Leo
Follow
Aug 2
CISA rewrites the SBOM floor: hashes are required, and the scope now covers AI and SaaS
#
sbom
#
cisa
#
supplychainsecurity
#
provenance
Comments
Add Comment
3 min read
npm walls off 2FA-bypass tokens from account and package management
Leo
Leo
Leo
Follow
Aug 1
npm walls off 2FA-bypass tokens from account and package management
#
npm
#
supplychainsecurity
#
2fa
#
accesstokens
Comments
Add Comment
3 min read
Supply Chain Attacks verstehen: Praktische Tipps zur Abwehr von 2026
Uhltak Therestismysecret
Uhltak Therestismysecret
Uhltak Therestismysecret
Follow
Jul 30
Supply Chain Attacks verstehen: Praktische Tipps zur Abwehr von 2026
#
supplychainsecurity
#
supplychainattacks
#
softwaredependencies
#
devsecops
Comments
Add Comment
6 min read
GTIG and Mandiant publish a supply-chain hardening playbook aimed at CI/CD teams
Leo
Leo
Leo
Follow
Jul 30
GTIG and Mandiant publish a supply-chain hardening playbook aimed at CI/CD teams
#
supplychainsecurity
#
gtig
#
mandiant
#
cicdsecurity
Comments
Add Comment
4 min read
OpenAI open-sources the Codex Security CLI and keeps the scanner in-house
Leo
Leo
Leo
Follow
Jul 30
OpenAI open-sources the Codex Security CLI and keeps the scanner in-house
#
openai
#
codex
#
supplychainsecurity
#
codescanning
Comments
Add Comment
4 min read
Docker's fourth horror story revisits the Nx post-install hook that drained CI secrets
Leo
Leo
Leo
Follow
Jul 29
Docker's fourth horror story revisits the Nx post-install hook that drained CI secrets
#
supplychainsecurity
#
npm
#
postinstallhooks
#
cirunners
Comments
Add Comment
3 min read
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account