DEV Community

#supplychain

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
xAI publishes Grok Build's source after the coding agent was caught siphoning SSH keys

xAI publishes Grok Build's source after the coding agent was caught siphoning SSH keys

Comments
3 min read
Mini Shai-Hulud: the tj-actions memory-dump script, reused fourteen months later

Mini Shai-Hulud: the tj-actions memory-dump script, reused fourteen months later

Comments
2 min read
The workstation is in scope now

The workstation is in scope now

Comments
3 min read
Clinejection: How a GitHub Issue Title Compromised an AI Coding Assistant Used by 5M Developers

Clinejection: How a GitHub Issue Title Compromised an AI Coding Assistant Used by 5M Developers

Comments
3 min read
GitLab tries to auto-fix the transitive-dep problem it keeps quantifying

GitLab tries to auto-fix the transitive-dep problem it keeps quantifying

Comments
5 min read
Cordyceps: when a stranger's pull request runs as a maintainer

Cordyceps: when a stranger's pull request runs as a maintainer

Comments
3 min read
Crunchyroll Hackeada: 100GB Robados vĂ­a un Empleado de Telus

Crunchyroll Hackeada: 100GB Robados vĂ­a un Empleado de Telus

Comments
5 min read
Inside the Chain: the tj-actions compromise wasn't one incident — it was three

Inside the Chain: the tj-actions compromise wasn't one incident — it was three

Comments
2 min read
Booking.com Breach: When the Vendor Chain Becomes the Attack Surface

Booking.com Breach: When the Vendor Chain Becomes the Attack Surface

1
Comments
2 min read
Dependabot learns to wait: version-update PRs now sit for three days by default

Dependabot learns to wait: version-update PRs now sit for three days by default

Comments
4 min read
Datadog says months-long GitHub recon out of dormant 'ghost' accounts is prep for supply-chain attacks

Datadog says months-long GitHub recon out of dormant 'ghost' accounts is prep for supply-chain attacks

1
Comments
2 min read
k8s-aibom writes down the AI your cluster is already running

k8s-aibom writes down the AI your cluster is already running

1
Comments
3 min read
HalluSquatting: the dependency your agent invented, and the attacker who registered it first

HalluSquatting: the dependency your agent invented, and the attacker who registered it first

Comments
3 min read
The five-minute SBOM sniff test earns its keep

The five-minute SBOM sniff test earns its keep

Comments
3 min read
Innersource security advisories go GA: a private channel for private vulns

Innersource security advisories go GA: a private channel for private vulns

Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.