Sponsored Content

DEV Community

#supplychain

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Popular projects SHA-pin GitHub Actions 67.6% of the time — but Docker base images only 7.6%

Popular projects SHA-pin GitHub Actions 67.6% of the time — but Docker base images only 7.6%

Comments
3 min read
A Supply-Chain Worm Wrote Itself Into Claude Code's Hook Files to Survive Credential Rotation

A Supply-Chain Worm Wrote Itself Into Claude Code's Hook Files to Survive Credential Rotation

Comments
2 min read
The Source Is Closed. Here's How You Can Still Trust the Supply Chain.

The Source Is Closed. Here's How You Can Still Trust the Supply Chain.

Comments
5 min read
Why Your Base Image Has 1,684 CVEs

Why Your Base Image Has 1,684 CVEs

Comments
16 min read
What Is JINGDONG Logistics and How Does JD Logistics Use AI in Supply Chain Management?

What Is JINGDONG Logistics and How Does JD Logistics Use AI in Supply Chain Management?

Comments
5 min read
npm provenance attestations get worn as camouflage in a new worm-style attack

npm provenance attestations get worn as camouflage in a new worm-style attack

Comments
5 min read
Fear Is the Mind-Killer. Dependencies Are the Build-Killer

Fear Is the Mind-Killer. Dependencies Are the Build-Killer

Comments
2 min read
A shared agent-plugin format is a shared supply chain

A shared agent-plugin format is a shared supply chain

Comments 1
3 min read
Your Coding Agent Has a Supply Chain, and You Probably Have Not Scoped It

Your Coding Agent Has a Supply Chain, and You Probably Have Not Scoped It

Comments
8 min read
RapidFort points its hardened open-source business at what actually runs in production

RapidFort points its hardened open-source business at what actually runs in production

1
Comments
2 min read
CodeQL 2.26.2 trims what counts as safe: fresh alerts incoming

CodeQL 2.26.2 trims what counts as safe: fresh alerts incoming

1
Comments
3 min read
The 72-hour dependency cooldown is security theater that breaks your builds

The 72-hour dependency cooldown is security theater that breaks your builds

3
Comments 2
3 min read
The Streak Continues: Four More Supply Chain Attacks Hit npm and PyPI

The Streak Continues: Four More Supply Chain Attacks Hit npm and PyPI

Comments
7 min read
Stop Slopsquatting With a CI Gate, Not a Better Prompt

Stop Slopsquatting With a CI Gate, Not a Better Prompt

Comments
4 min read
Image verification, one layer below admission

Image verification, one layer below admission

Comments
2 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.