DEV Community

#supplychainsecurity

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
RubyGems Supply Chain Vulnerability: What the OpenAI Bot Incident Teaches About Node.js and npm Security

RubyGems Supply Chain Vulnerability: What the OpenAI Bot Incident Teaches About Node.js and npm Security

Comments
7 min read
Supply Chain Security 2026: SBOM, Sigstore/SLSA, and Admission Control as DevOps Standard

Supply Chain Security 2026: SBOM, Sigstore/SLSA, and Admission Control as DevOps Standard

Comments
4 min read
Software Artifact Trust Starts At Package Registries

Software Artifact Trust Starts At Package Registries

Comments
2 min read
No CVE Is Coming for Android-Image-Cropper. Audit Anyway.

No CVE Is Coming for Android-Image-Cropper. Audit Anyway.

Comments
3 min read
Container Image Signing & SLSA Provenance Verification with Sigstore Cosign

Container Image Signing & SLSA Provenance Verification with Sigstore Cosign

Comments
4 min read
The LiteLLM compromise is not in any of the places you would look for it

The LiteLLM compromise is not in any of the places you would look for it

Comments
4 min read
CNCF's shadow-AI post makes the case for treating agents as identities

CNCF's shadow-AI post makes the case for treating agents as identities

Comments
3 min read
Omdia's 2026 supply-chain survey puts the annual-incident rate at 77 percent

Omdia's 2026 supply-chain survey puts the annual-incident rate at 77 percent

1
Comments
2 min read
CISA's new OSS guidance puts a four-letter scoreboard next to every dependency you ship

CISA's new OSS guidance puts a four-letter scoreboard next to every dependency you ship

Comments 1
3 min read
CISA rewrites the SBOM floor: hashes are required, and the scope now covers AI and SaaS

CISA rewrites the SBOM floor: hashes are required, and the scope now covers AI and SaaS

Comments
3 min read
npm walls off 2FA-bypass tokens from account and package management

npm walls off 2FA-bypass tokens from account and package management

Comments
3 min read
Supply Chain Attacks verstehen: Praktische Tipps zur Abwehr von 2026

Supply Chain Attacks verstehen: Praktische Tipps zur Abwehr von 2026

Comments
6 min read
GTIG and Mandiant publish a supply-chain hardening playbook aimed at CI/CD teams

GTIG and Mandiant publish a supply-chain hardening playbook aimed at CI/CD teams

Comments
4 min read
OpenAI open-sources the Codex Security CLI and keeps the scanner in-house

OpenAI open-sources the Codex Security CLI and keeps the scanner in-house

Comments
4 min read
Docker's fourth horror story revisits the Nx post-install hook that drained CI secrets

Docker's fourth horror story revisits the Nx post-install hook that drained CI secrets

Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.