Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
#
supplychainsecurity
Follow
Hide
Posts
Left menu
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
Container Image Signing & SLSA Provenance Verification with Sigstore Cosign
Aomi Qaza
Aomi Qaza
Aomi Qaza
Follow
Aug 15
Container Image Signing & SLSA Provenance Verification with Sigstore Cosign
#
supplychainsecurity
#
devops
Comments
Add Comment
4 min read
The LiteLLM compromise is not in any of the places you would look for it
Imran Siddique
Imran Siddique
Imran Siddique
Follow
Aug 14
The LiteLLM compromise is not in any of the places you would look for it
#
supplychainsecurity
#
cicd
#
security
#
devops
Comments
Add Comment
4 min read
CNCF's shadow-AI post makes the case for treating agents as identities
Leo
Leo
Leo
Follow
Aug 9
CNCF's shadow-AI post makes the case for treating agents as identities
#
shadowai
#
supplychainsecurity
#
cncf
#
kubernetes
Comments
Add Comment
3 min read
Omdia's 2026 supply-chain survey puts the annual-incident rate at 77 percent
Leo
Leo
Leo
Follow
Aug 4
Omdia's 2026 supply-chain survey puts the annual-incident rate at 77 percent
#
supplychainsecurity
#
sbom
#
containers
#
cicdsecurity
1
 reaction
Comments
Add Comment
2 min read
CISA's new OSS guidance puts a four-letter scoreboard next to every dependency you ship
Leo
Leo
Leo
Follow
Aug 3
CISA's new OSS guidance puts a four-letter scoreboard next to every dependency you ship
#
cisa
#
supplychainsecurity
#
opensource
#
dependencies
Comments
1
 comment
3 min read
CISA rewrites the SBOM floor: hashes are required, and the scope now covers AI and SaaS
Leo
Leo
Leo
Follow
Aug 2
CISA rewrites the SBOM floor: hashes are required, and the scope now covers AI and SaaS
#
sbom
#
cisa
#
supplychainsecurity
#
provenance
Comments
Add Comment
3 min read
npm walls off 2FA-bypass tokens from account and package management
Leo
Leo
Leo
Follow
Aug 1
npm walls off 2FA-bypass tokens from account and package management
#
npm
#
supplychainsecurity
#
2fa
#
accesstokens
Comments
Add Comment
3 min read
Supply Chain Attacks verstehen: Praktische Tipps zur Abwehr von 2026
Uhltak Therestismysecret
Uhltak Therestismysecret
Uhltak Therestismysecret
Follow
Jul 30
Supply Chain Attacks verstehen: Praktische Tipps zur Abwehr von 2026
#
supplychainsecurity
#
supplychainattacks
#
softwaredependencies
#
devsecops
Comments
Add Comment
6 min read
GTIG and Mandiant publish a supply-chain hardening playbook aimed at CI/CD teams
Leo
Leo
Leo
Follow
Jul 30
GTIG and Mandiant publish a supply-chain hardening playbook aimed at CI/CD teams
#
supplychainsecurity
#
gtig
#
mandiant
#
cicdsecurity
Comments
Add Comment
4 min read
OpenAI open-sources the Codex Security CLI and keeps the scanner in-house
Leo
Leo
Leo
Follow
Jul 30
OpenAI open-sources the Codex Security CLI and keeps the scanner in-house
#
openai
#
codex
#
supplychainsecurity
#
codescanning
Comments
Add Comment
4 min read
Docker's fourth horror story revisits the Nx post-install hook that drained CI secrets
Leo
Leo
Leo
Follow
Jul 29
Docker's fourth horror story revisits the Nx post-install hook that drained CI secrets
#
supplychainsecurity
#
npm
#
postinstallhooks
#
cirunners
Comments
Add Comment
3 min read
GitHub Actions freezes suspected-malicious workflow runs until a human signs off
Leo
Leo
Leo
Follow
Jul 28
GitHub Actions freezes suspected-malicious workflow runs until a human signs off
#
githubactions
#
supplychainsecurity
#
workflowapproval
#
cicdsecurity
Comments
Add Comment
4 min read
Dependabot's 3-Day Cooldown: Why Waiting Is Now Safer
Induwara Ashinsana
Induwara Ashinsana
Induwara Ashinsana
Follow
Jul 24
Dependabot's 3-Day Cooldown: Why Waiting Is Now Safer
#
supplychainsecurity
#
dependabot
#
npm
Comments
Add Comment
4 min read
FakeGit floods GitHub with malicious repos aimed at coding agents
Leo
Leo
Leo
Follow
Jul 24
FakeGit floods GitHub with malicious repos aimed at coding agents
#
supplychainsecurity
#
codingagents
#
github
#
malware
Comments
Add Comment
2 min read
The npm worm that shipped with valid SLSA provenance
Leo
Leo
Leo
Follow
Jul 22
The npm worm that shipped with valid SLSA provenance
#
supplychainsecurity
#
slsa
#
provenance
#
npm
Comments
Add Comment
4 min read
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account