Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
#
supplychain
Follow
Hide
Posts
Left menu
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
Three merged PRs in an MCP security scanner: the review that found my bug, and two more
Edison Flores
Edison Flores
Edison Flores
Follow
Oct 3
Three merged PRs in an MCP security scanner: the review that found my bug, and two more
#
mcp
#
security
#
supplychain
#
python
Comments
Add Comment
4 min read
Container Image Provenance: Signing Is Half the Control
kozhevniko
kozhevniko
kozhevniko
Follow
Oct 3
Container Image Provenance: Signing Is Half the Control
#
security
#
containers
#
supplychain
Comments
Add Comment
2 min read
Rotating Credentials Is Not Revoking Them. The Revocation Unit Decides Whether You Can.
NTCTech
NTCTech
NTCTech
Follow
Oct 2
Rotating Credentials Is Not Revoking Them. The Revocation Unit Decides Whether You Can.
#
security
#
devops
#
architecture
#
supplychain
Comments
Add Comment
8 min read
Two Flaws, One Chain: How JFrog Artifactory Was Pushed to Admin
kozhevniko
kozhevniko
kozhevniko
Follow
Oct 1
Two Flaws, One Chain: How JFrog Artifactory Was Pushed to Admin
#
security
#
jfrog
#
artifactory
#
supplychain
Comments
Add Comment
4 min read
CVE-2026-60004: code injection through the Gitea diffpatch API, and why a forge holds everything
OnaEiuspkz
OnaEiuspkz
OnaEiuspkz
Follow
Oct 1
CVE-2026-60004: code injection through the Gitea diffpatch API, and why a forge holds everything
#
gitea
#
supplychain
#
codeinjection
Comments
Add Comment
2 min read
GitHub Actions Removed Node 20. Find Every node20 Action You Still Run
DevOps Daily
DevOps Daily
DevOps Daily
Follow
Oct 1
GitHub Actions Removed Node 20. Find Every node20 Action You Still Run
#
cicd
#
githubactions
#
node
#
supplychain
4
 reactions
Comments
Add Comment
14 min read
Browser extensions are an enterprise control problem, not a user hygiene problem
jeffrey
jeffrey
jeffrey
Follow
Oct 1
Browser extensions are an enterprise control problem, not a user hygiene problem
#
browsersecurity
#
extensionmanagement
#
enterprisepolicy
#
supplychain
1
 reaction
Comments
Add Comment
4 min read
When the Artifact Repository Is the Target: JFrog Artifactory and the Software Supply Chain Chokepoint
StarkMan
StarkMan
StarkMan
Follow
Sep 30
When the Artifact Repository Is the Target: JFrog Artifactory and the Software Supply Chain Chokepoint
#
security
#
supplychain
#
vulnerabilitymanagement
Comments
Add Comment
3 min read
GitHub Actions Supply Chain Risk: Pinning, OIDC and Least-Privilege Tokens
OnaEiuspkz
OnaEiuspkz
OnaEiuspkz
Follow
Oct 1
GitHub Actions Supply Chain Risk: Pinning, OIDC and Least-Privilege Tokens
#
supplychain
#
cicd
#
githubactions
1
 reaction
Comments
Add Comment
2 min read
Brevo: A Cloudflare Worker That Rewrote a Marketing Platform in Flight
yutianle
yutianle
yutianle
Follow
Sep 30
Brevo: A Cloudflare Worker That Rewrote a Marketing Platform in Flight
#
supplychain
#
cdn
#
wordpress
#
clickfix
Comments
Add Comment
2 min read
yarn.lock: may the `--force` be with you
Anton Golub
Anton Golub
Anton Golub
Follow
Sep 29
yarn.lock: may the `--force` be with you
#
javascript
#
security
#
npm
#
supplychain
1
 reaction
Comments
1
 comment
14 min read
yarn.lock: you can't `sed` a graph
Anton Golub
Anton Golub
Anton Golub
Follow
Sep 29
yarn.lock: you can't `sed` a graph
#
javascript
#
npm
#
supplychain
#
security
1
 reaction
Comments
1
 comment
10 min read
yarn audit [still does not] fix
Anton Golub
Anton Golub
Anton Golub
Follow
Sep 29
yarn audit [still does not] fix
#
javascript
#
security
#
tools
#
supplychain
1
 reaction
Comments
Add Comment
9 min read
Verdaccio on 3,336 hosts: private npm registries and the tokens they hand out
StarkMan
StarkMan
StarkMan
Follow
Sep 28
Verdaccio on 3,336 hosts: private npm registries and the tokens they hand out
#
security
#
zoomeye
#
exposure
#
supplychain
Comments
1
 comment
3 min read
Artifact Repositories Are Trust Anchors: Incident Response for a Compromised Build Pipeline
jeffrey
jeffrey
jeffrey
Follow
Sep 25
Artifact Repositories Are Trust Anchors: Incident Response for a Compromised Build Pipeline
#
security
#
supplychain
#
incidentresponse
#
artifactory
Comments
Add Comment
3 min read
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account