Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
#
supplychain
Follow
Hide
Posts
Left menu
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
xAI publishes Grok Build's source after the coding agent was caught siphoning SSH keys
Leo
Leo
Leo
Follow
Jul 21
xAI publishes Grok Build's source after the coding agent was caught siphoning SSH keys
#
codingagents
#
supplychain
#
security
#
sshkeys
Comments
Add Comment
3 min read
Mini Shai-Hulud: the tj-actions memory-dump script, reused fourteen months later
Eldor Zufarov
Eldor Zufarov
Eldor Zufarov
Follow
Jul 20
Mini Shai-Hulud: the tj-actions memory-dump script, reused fourteen months later
#
devsecops
#
security
#
supplychain
#
cicd
Comments
Add Comment
2 min read
The workstation is in scope now
Leo
Leo
Leo
Follow
Jul 19
The workstation is in scope now
#
supplychain
#
developerworkstation
#
githubactions
#
vscode
Comments
Add Comment
3 min read
Clinejection: How a GitHub Issue Title Compromised an AI Coding Assistant Used by 5M Developers
Eldor Zufarov
Eldor Zufarov
Eldor Zufarov
Follow
Jul 19
Clinejection: How a GitHub Issue Title Compromised an AI Coding Assistant Used by 5M Developers
#
appsec
#
supplychain
#
devsecops
#
ai
Comments
Add Comment
3 min read
GitLab tries to auto-fix the transitive-dep problem it keeps quantifying
Leo
Leo
Leo
Follow
Jul 17
GitLab tries to auto-fix the transitive-dep problem it keeps quantifying
#
gitlab
#
supplychain
#
dependencies
#
autoremediation
Comments
Add Comment
5 min read
Cordyceps: when a stranger's pull request runs as a maintainer
Leo
Leo
Leo
Follow
Jul 16
Cordyceps: when a stranger's pull request runs as a maintainer
#
supplychain
#
githubactions
#
workflowsecurity
#
pullrequesttarget
Comments
Add Comment
3 min read
Crunchyroll Hackeada: 100GB Robados vĂa un Empleado de Telus
Diego Diaz
Diego Diaz
Diego Diaz
Follow
Jul 16
Crunchyroll Hackeada: 100GB Robados vĂa un Empleado de Telus
#
breach
#
supplychain
#
streaming
#
sony
Comments
Add Comment
5 min read
Inside the Chain: the tj-actions compromise wasn't one incident — it was three
Eldor Zufarov
Eldor Zufarov
Eldor Zufarov
Follow
Jul 16
Inside the Chain: the tj-actions compromise wasn't one incident — it was three
#
devsecops
#
security
#
supplychain
#
cicd
Comments
Add Comment
2 min read
Booking.com Breach: When the Vendor Chain Becomes the Attack Surface
Diego Diaz
Diego Diaz
Diego Diaz
Follow
Jul 16
Booking.com Breach: When the Vendor Chain Becomes the Attack Surface
#
breach
#
booking
#
vendorchain
#
supplychain
1
 reaction
Comments
Add Comment
2 min read
Dependabot learns to wait: version-update PRs now sit for three days by default
Leo
Leo
Leo
Follow
Jul 15
Dependabot learns to wait: version-update PRs now sit for three days by default
#
dependabot
#
github
#
supplychain
#
packageupdates
Comments
Add Comment
4 min read
Datadog says months-long GitHub recon out of dormant 'ghost' accounts is prep for supply-chain attacks
Leo
Leo
Leo
Follow
Jul 14
Datadog says months-long GitHub recon out of dormant 'ghost' accounts is prep for supply-chain attacks
#
github
#
supplychain
#
security
#
reconnaissance
1
 reaction
Comments
Add Comment
2 min read
k8s-aibom writes down the AI your cluster is already running
Leo
Leo
Leo
Follow
Jul 14
k8s-aibom writes down the AI your cluster is already running
#
supplychain
#
aibom
#
cyclonedx
#
kubernetes
1
 reaction
Comments
Add Comment
3 min read
HalluSquatting: the dependency your agent invented, and the attacker who registered it first
Leo
Leo
Leo
Follow
Jul 13
HalluSquatting: the dependency your agent invented, and the attacker who registered it first
#
supplychain
#
aicodingagents
#
packagehallucination
#
dependencyscanning
Comments
Add Comment
3 min read
The five-minute SBOM sniff test earns its keep
Leo
Leo
Leo
Follow
Jul 13
The five-minute SBOM sniff test earns its keep
#
supplychain
#
sbom
#
hardenedimages
#
security
Comments
Add Comment
3 min read
Innersource security advisories go GA: a private channel for private vulns
Leo
Leo
Leo
Follow
Jul 11
Innersource security advisories go GA: a private channel for private vulns
#
github
#
ghas
#
dependabot
#
supplychain
Comments
Add Comment
3 min read
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account