DEV Community

# supplychain

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
CI is the wrong place to first hear about your npm dependencies

CI is the wrong place to first hear about your npm dependencies

Comments
3 min read
PostCSS Adopted Staged Publishing. 685M Weekly Downloads Now Gated.

PostCSS Adopted Staged Publishing. 685M Weekly Downloads Now Gated.

2
Comments 1
2 min read
Come ragiona un hacker (e cosa cambia per chi costruisce prodotti web)

Come ragiona un hacker (e cosa cambia per chi costruisce prodotti web)

Comments
4 min read
Cilium publishes its CI hardening playbook, gaps and all

Cilium publishes its CI hardening playbook, gaps and all

Comments
3 min read
SP Page Builder ships a one-file controller patch in 6.6.2, and the locked support thread is a reminder that patching isn't cleanup

SP Page Builder ships a one-file controller patch in 6.6.2, and the locked support thread is a reminder that patching isn't cleanup

Comments
6 min read
npm freezes high-impact maintainer accounts for 72 hours after a sensitive change

npm freezes high-impact maintainer accounts for 72 hours after a sensitive change

Comments
4 min read
A Rogue Registry in My Own Backyard: Anatomy of a Two-Line Supply Chain Attack

A Rogue Registry in My Own Backyard: Anatomy of a Two-Line Supply Chain Attack

1
Comments
6 min read
What 5 Years on an Amazon Dock Taught Me About Barcodes

What 5 Years on an Amazon Dock Taught Me About Barcodes

Comments
2 min read
Homebrew 6.0.0 turns third-party taps into an opt-in trust list

Homebrew 6.0.0 turns third-party taps into an opt-in trust list

Comments
3 min read
Your auth library's maintainer is an agent who never sleeps

Your auth library's maintainer is an agent who never sleeps

Comments
5 min read
From Supply Chain to Software: What Containers Actually Are and Why They Matter

From Supply Chain to Software: What Containers Actually Are and Why They Matter

Comments
6 min read
One npm Account Publishes 964 Million Downloads Per Week. None Have Provenance.

One npm Account Publishes 964 Million Downloads Per Week. None Have Provenance.

Comments
3 min read
Local LLM Security Best Practices: Beyond Basic Hashing

Local LLM Security Best Practices: Beyond Basic Hashing

Comments
4 min read
How to Build a Secure Homelab for LLM Inference

How to Build a Secure Homelab for LLM Inference

Comments
4 min read
Chainguard's drop-in Java libraries trade a framework upgrade for an SLA

Chainguard's drop-in Java libraries trade a framework upgrade for an SLA

1
Comments 1
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.