DEV Community

#supplychain

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Brevo: A Cloudflare Worker That Rewrote a Marketing Platform in Flight

Brevo: A Cloudflare Worker That Rewrote a Marketing Platform in Flight

Comments
2 min read
yarn.lock: may the `--force` be with you

yarn.lock: may the `--force` be with you

1
Comments 1
14 min read
yarn.lock: you can't `sed` a graph

yarn.lock: you can't `sed` a graph

1
Comments 1
10 min read
yarn audit [still does not] fix

yarn audit [still does not] fix

1
Comments
9 min read
Verdaccio on 3,336 hosts: private npm registries and the tokens they hand out

Verdaccio on 3,336 hosts: private npm registries and the tokens they hand out

Comments 1
3 min read
Artifact Repositories Are Trust Anchors: Incident Response for a Compromised Build Pipeline

Artifact Repositories Are Trust Anchors: Incident Response for a Compromised Build Pipeline

Comments
3 min read
GitHub got pwned through one VSCode extension. 3,800 repos.

GitHub got pwned through one VSCode extension. 3,800 repos.

Comments
5 min read
CVE-2026-96365 and the Contribution Model: Why Drupal Site Owners Carry the Patch Burden

CVE-2026-96365 and the Contribution Model: Why Drupal Site Owners Carry the Patch Burden

1
Comments
2 min read
The JFrog Artifactory authentication bypass: when an empty signing key becomes an admin token

The JFrog Artifactory authentication bypass: when an empty signing key becomes an admin token

Comments
3 min read
The Credential Relay Economy: How Supply Chain Attacks Chain Through SaaS Vendors

The Credential Relay Economy: How Supply Chain Attacks Chain Through SaaS Vendors

Comments
2 min read
Software Supply Chains Have an Address: Mapping Exposed Artifact Repositories with ZoomEye

Software Supply Chains Have an Address: Mapping Exposed Artifact Repositories with ZoomEye

Comments
3 min read
The Artifactory Token Chain: Why Build Repositories Are a Credential Store

The Artifactory Token Chain: Why Build Repositories Are a Credential Store

Comments
4 min read
The Artifact Repository Is a Trust Root: Reading the JFrog Artifactory Authentication Bypass

The Artifact Repository Is a Trust Root: Reading the JFrog Artifactory Authentication Bypass

Comments
4 min read
The Shai-Hulud npm worm showed that opening a folder is enough to run code

The Shai-Hulud npm worm showed that opening a folder is enough to run code

Comments
3 min read
Print Servers and Artifact Repositories: Measuring Two Overlooked Attack Surfaces

Print Servers and Artifact Repositories: Measuring Two Overlooked Attack Surfaces

Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.