DEV Community

#supplychain

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
1,316,357 GitLab Matches and 456,436 Title Matches: Sizing a Self-Managed Code Host

1,316,357 GitLab Matches and 456,436 Title Matches: Sizing a Self-Managed Code Host

Comments
3 min read
The npm worm playbook for a small team

The npm worm playbook for a small team

Comments
6 min read
ChainDrop Had Valid Provenance. That Was Not Enough.

ChainDrop Had Valid Provenance. That Was Not Enough.

Comments 1
2 min read
1538 Jenkins, 169 Harbor and 32 SonarQube Results: The Build Chain Has a Public Address

1538 Jenkins, 169 Harbor and 32 SonarQube Results: The Build Chain Has a Public Address

Comments
4 min read
Beyond the package name: why following the call is the hard part of supply-chain security

Beyond the package name: why following the call is the hard part of supply-chain security

Comments
3 min read
What Ed25519 Signing Actually Proves About a Test Result

What Ed25519 Signing Actually Proves About a Test Result

Comments
6 min read
oc-mirror CVE-2026-75939: A Signature Check That Runs in the Wrong Order

oc-mirror CVE-2026-75939: A Signature Check That Runs in the Wrong Order

Comments
2 min read
Nexus Repository Manager: 81,550 title matches and 33,844 fingerprints on the artefact pipeline everything depends on

Nexus Repository Manager: 81,550 title matches and 33,844 fingerprints on the artefact pipeline everything depends on

Comments
2 min read
Three merged PRs in an MCP security scanner: the review that found my bug, and two more

Three merged PRs in an MCP security scanner: the review that found my bug, and two more

Comments
4 min read
Container Image Provenance: Signing Is Half the Control

Container Image Provenance: Signing Is Half the Control

Comments
2 min read
Rotating Credentials Is Not Revoking Them. The Revocation Unit Decides Whether You Can.

Rotating Credentials Is Not Revoking Them. The Revocation Unit Decides Whether You Can.

Comments
8 min read
Two Flaws, One Chain: How JFrog Artifactory Was Pushed to Admin

Two Flaws, One Chain: How JFrog Artifactory Was Pushed to Admin

Comments
4 min read
CVE-2026-60004: code injection through the Gitea diffpatch API, and why a forge holds everything

CVE-2026-60004: code injection through the Gitea diffpatch API, and why a forge holds everything

Comments
2 min read
GitHub Actions Removed Node 20. Find Every node20 Action You Still Run

GitHub Actions Removed Node 20. Find Every node20 Action You Still Run

4
Comments
14 min read
Browser extensions are an enterprise control problem, not a user hygiene problem

Browser extensions are an enterprise control problem, not a user hygiene problem

1
Comments
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.