Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
#
supplychain
Follow
Hide
Posts
Left menu
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
Brevo: A Cloudflare Worker That Rewrote a Marketing Platform in Flight
yutianle
yutianle
yutianle
Follow
Sep 30
Brevo: A Cloudflare Worker That Rewrote a Marketing Platform in Flight
#
supplychain
#
cdn
#
wordpress
#
clickfix
Comments
Add Comment
2 min read
yarn.lock: may the `--force` be with you
Anton Golub
Anton Golub
Anton Golub
Follow
Sep 29
yarn.lock: may the `--force` be with you
#
javascript
#
security
#
npm
#
supplychain
1
 reaction
Comments
1
 comment
14 min read
yarn.lock: you can't `sed` a graph
Anton Golub
Anton Golub
Anton Golub
Follow
Sep 29
yarn.lock: you can't `sed` a graph
#
javascript
#
npm
#
supplychain
#
security
1
 reaction
Comments
1
 comment
10 min read
yarn audit [still does not] fix
Anton Golub
Anton Golub
Anton Golub
Follow
Sep 29
yarn audit [still does not] fix
#
javascript
#
security
#
tools
#
supplychain
1
 reaction
Comments
Add Comment
9 min read
Verdaccio on 3,336 hosts: private npm registries and the tokens they hand out
StarkMan
StarkMan
StarkMan
Follow
Sep 28
Verdaccio on 3,336 hosts: private npm registries and the tokens they hand out
#
security
#
zoomeye
#
exposure
#
supplychain
Comments
1
 comment
3 min read
Artifact Repositories Are Trust Anchors: Incident Response for a Compromised Build Pipeline
jeffrey
jeffrey
jeffrey
Follow
Sep 25
Artifact Repositories Are Trust Anchors: Incident Response for a Compromised Build Pipeline
#
security
#
supplychain
#
incidentresponse
#
artifactory
Comments
Add Comment
3 min read
GitHub got pwned through one VSCode extension. 3,800 repos.
Ritabrata Maiti
Ritabrata Maiti
Ritabrata Maiti
Follow
Sep 24
GitHub got pwned through one VSCode extension. 3,800 repos.
#
github
#
vscode
#
security
#
supplychain
Comments
Add Comment
5 min read
CVE-2026-96365 and the Contribution Model: Why Drupal Site Owners Carry the Patch Burden
OnaEiuspkz
OnaEiuspkz
OnaEiuspkz
Follow
Sep 29
CVE-2026-96365 and the Contribution Model: Why Drupal Site Owners Carry the Patch Burden
#
security
#
drupal
#
cve202696365
#
supplychain
1
 reaction
Comments
Add Comment
2 min read
The JFrog Artifactory authentication bypass: when an empty signing key becomes an admin token
StarkMan
StarkMan
StarkMan
Follow
Sep 24
The JFrog Artifactory authentication bypass: when an empty signing key becomes an admin token
#
supplychain
#
artifactrepository
#
authenticationbypass
#
jfrog
Comments
Add Comment
3 min read
The Credential Relay Economy: How Supply Chain Attacks Chain Through SaaS Vendors
jeffrey
jeffrey
jeffrey
Follow
Sep 23
The Credential Relay Economy: How Supply Chain Attacks Chain Through SaaS Vendors
#
supplychain
#
credentials
#
saassecurity
Comments
Add Comment
2 min read
Software Supply Chains Have an Address: Mapping Exposed Artifact Repositories with ZoomEye
jeffrey
jeffrey
jeffrey
Follow
Sep 23
Software Supply Chains Have an Address: Mapping Exposed Artifact Repositories with ZoomEye
#
supplychain
#
attacksurface
#
zoomeye
#
exposuremanagement
Comments
Add Comment
3 min read
The Artifactory Token Chain: Why Build Repositories Are a Credential Store
kozhevniko
kozhevniko
kozhevniko
Follow
Sep 21
The Artifactory Token Chain: Why Build Repositories Are a Credential Store
#
supplychain
#
artifactrepository
#
authenticationbypass
#
devsecops
Comments
Add Comment
4 min read
The Artifact Repository Is a Trust Root: Reading the JFrog Artifactory Authentication Bypass
jeffrey
jeffrey
jeffrey
Follow
Sep 20
The Artifact Repository Is a Trust Root: Reading the JFrog Artifactory Authentication Bypass
#
supplychain
#
devops
#
authentication
#
artifactrepository
Comments
Add Comment
4 min read
The Shai-Hulud npm worm showed that opening a folder is enough to run code
yutianle
yutianle
yutianle
Follow
Sep 20
The Shai-Hulud npm worm showed that opening a folder is enough to run code
#
supplychain
#
npm
#
developertooling
#
credentialtheft
Comments
Add Comment
3 min read
Print Servers and Artifact Repositories: Measuring Two Overlooked Attack Surfaces
kozhevniko
kozhevniko
kozhevniko
Follow
Sep 20
Print Servers and Artifact Repositories: Measuring Two Overlooked Attack Surfaces
#
security
#
zoomeye
#
exposure
#
supplychain
Comments
Add Comment
3 min read
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account