DEV Community

#supplychain

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Three merged PRs in an MCP security scanner: the review that found my bug, and two more

Three merged PRs in an MCP security scanner: the review that found my bug, and two more

Comments
4 min read
Container Image Provenance: Signing Is Half the Control

Container Image Provenance: Signing Is Half the Control

Comments
2 min read
Rotating Credentials Is Not Revoking Them. The Revocation Unit Decides Whether You Can.

Rotating Credentials Is Not Revoking Them. The Revocation Unit Decides Whether You Can.

Comments
8 min read
Two Flaws, One Chain: How JFrog Artifactory Was Pushed to Admin

Two Flaws, One Chain: How JFrog Artifactory Was Pushed to Admin

Comments
4 min read
CVE-2026-60004: code injection through the Gitea diffpatch API, and why a forge holds everything

CVE-2026-60004: code injection through the Gitea diffpatch API, and why a forge holds everything

Comments
2 min read
GitHub Actions Removed Node 20. Find Every node20 Action You Still Run

GitHub Actions Removed Node 20. Find Every node20 Action You Still Run

4
Comments
14 min read
Browser extensions are an enterprise control problem, not a user hygiene problem

Browser extensions are an enterprise control problem, not a user hygiene problem

1
Comments
4 min read
When the Artifact Repository Is the Target: JFrog Artifactory and the Software Supply Chain Chokepoint

When the Artifact Repository Is the Target: JFrog Artifactory and the Software Supply Chain Chokepoint

Comments
3 min read
GitHub Actions Supply Chain Risk: Pinning, OIDC and Least-Privilege Tokens

GitHub Actions Supply Chain Risk: Pinning, OIDC and Least-Privilege Tokens

1
Comments
2 min read
Brevo: A Cloudflare Worker That Rewrote a Marketing Platform in Flight

Brevo: A Cloudflare Worker That Rewrote a Marketing Platform in Flight

Comments
2 min read
yarn.lock: may the `--force` be with you

yarn.lock: may the `--force` be with you

1
Comments 1
14 min read
yarn.lock: you can't `sed` a graph

yarn.lock: you can't `sed` a graph

1
Comments 1
10 min read
yarn audit [still does not] fix

yarn audit [still does not] fix

1
Comments
9 min read
Verdaccio on 3,336 hosts: private npm registries and the tokens they hand out

Verdaccio on 3,336 hosts: private npm registries and the tokens they hand out

Comments 1
3 min read
Artifact Repositories Are Trust Anchors: Incident Response for a Compromised Build Pipeline

Artifact Repositories Are Trust Anchors: Incident Response for a Compromised Build Pipeline

Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.