Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
#
supplychain
Follow
Hide
Posts
Left menu
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
Your Coding Agent Has a Supply Chain, and You Probably Have Not Scoped It
Mike Dabydeen
Mike Dabydeen
Mike Dabydeen
Follow
Aug 10
Your Coding Agent Has a Supply Chain, and You Probably Have Not Scoped It
#
security
#
devops
#
supplychain
#
ai
Comments
Add Comment
8 min read
RapidFort points its hardened open-source business at what actually runs in production
Leo
Leo
Leo
Follow
Aug 10
RapidFort points its hardened open-source business at what actually runs in production
#
runtimesecurity
#
supplychain
#
opensource
#
monitoring
1
 reaction
Comments
Add Comment
2 min read
CodeQL 2.26.2 trims what counts as safe: fresh alerts incoming
Leo
Leo
Leo
Follow
Aug 10
CodeQL 2.26.2 trims what counts as safe: fresh alerts incoming
#
codeql
#
githubactions
#
sast
#
supplychain
1
 reaction
Comments
Add Comment
3 min read
The Streak Continues: Four More Supply Chain Attacks Hit npm and PyPI
Dwayne McDaniel
Dwayne McDaniel
Dwayne McDaniel
Follow
for
GitGuardian
Jul 31
The Streak Continues: Four More Supply Chain Attacks Hit npm and PyPI
#
security
#
supplychain
#
npm
#
python
Comments
Add Comment
7 min read
Stop Slopsquatting With a CI Gate, Not a Better Prompt
jaryn
jaryn
jaryn
Follow
Jul 31
Stop Slopsquatting With a CI Gate, Not a Better Prompt
#
security
#
ai
#
supplychain
#
devsecops
Comments
Add Comment
4 min read
Image verification, one layer below admission
Leo
Leo
Leo
Follow
Jul 31
Image verification, one layer below admission
#
kubernetes
#
supplychain
#
policy
#
attestations
Comments
Add Comment
2 min read
PyPI stops accepting late file uploads to releases older than 14 days
Leo
Leo
Leo
Follow
Jul 28
PyPI stops accepting late file uploads to releases older than 14 days
#
supplychain
#
pypi
#
python
#
dependabot
Comments
Add Comment
3 min read
Agentic Supply Chain Vulnerabilities: Your Agent Is Only as Secure as Its Weakest Plugin (ASI04)
Maish Saidel-Keesing
Maish Saidel-Keesing
Maish Saidel-Keesing
Follow
for
AWS
Jul 21
Agentic Supply Chain Vulnerabilities: Your Agent Is Only as Secure as Its Weakest Plugin (ASI04)
#
aws
#
security
#
supplychain
#
ai
1
 reaction
Comments
Add Comment
10 min read
xAI publishes Grok Build's source after the coding agent was caught siphoning SSH keys
Leo
Leo
Leo
Follow
Jul 21
xAI publishes Grok Build's source after the coding agent was caught siphoning SSH keys
#
codingagents
#
supplychain
#
security
#
sshkeys
Comments
Add Comment
3 min read
Mini Shai-Hulud: the tj-actions memory-dump script, reused fourteen months later
Eldor Zufarov
Eldor Zufarov
Eldor Zufarov
Follow
Jul 20
Mini Shai-Hulud: the tj-actions memory-dump script, reused fourteen months later
#
devsecops
#
security
#
supplychain
#
cicd
Comments
Add Comment
2 min read
The workstation is in scope now
Leo
Leo
Leo
Follow
Jul 19
The workstation is in scope now
#
supplychain
#
developerworkstation
#
githubactions
#
vscode
Comments
Add Comment
3 min read
Clinejection: How a GitHub Issue Title Compromised an AI Coding Assistant Used by 5M Developers
Eldor Zufarov
Eldor Zufarov
Eldor Zufarov
Follow
Jul 19
Clinejection: How a GitHub Issue Title Compromised an AI Coding Assistant Used by 5M Developers
#
appsec
#
supplychain
#
devsecops
#
ai
Comments
Add Comment
3 min read
The pwn request just got harder: what actions/checkout v7 changes, and what it does not
DevOps Daily
DevOps Daily
DevOps Daily
Follow
Aug 10
The pwn request just got harder: what actions/checkout v7 changes, and what it does not
#
cicd
#
githubactions
#
security
#
supplychain
1
 reaction
Comments
Add Comment
10 min read
GitLab tries to auto-fix the transitive-dep problem it keeps quantifying
Leo
Leo
Leo
Follow
Jul 17
GitLab tries to auto-fix the transitive-dep problem it keeps quantifying
#
gitlab
#
supplychain
#
dependencies
#
autoremediation
Comments
Add Comment
5 min read
Cordyceps: when a stranger's pull request runs as a maintainer
Leo
Leo
Leo
Follow
Jul 16
Cordyceps: when a stranger's pull request runs as a maintainer
#
supplychain
#
githubactions
#
workflowsecurity
#
pullrequesttarget
Comments
Add Comment
3 min read
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account