Forem

# supplychain

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
FIDO2 for CI/CD: Why Origin-Bound Hardware Authentication Beats TOTP and Push Approvals

FIDO2 for CI/CD: Why Origin-Bound Hardware Authentication Beats TOTP and Push Approvals

Comments
3 min read
Plausible Compliance: Designing Duress Protocols for Human Coercion in CI/CD Security

Plausible Compliance: Designing Duress Protocols for Human Coercion in CI/CD Security

Comments
3 min read
The Anthropic SDK Looks Safe. Two of Its Transitive Dependencies Aren't.

The Anthropic SDK Looks Safe. Two of Its Transitive Dependencies Aren't.

Comments
3 min read
You can now explore npm dependency trees visually — see transitive CRITICAL risks in seconds

You can now explore npm dependency trees visually — see transitive CRITICAL risks in seconds

Comments
2 min read
The Anthropic SDK Depends on 2 CRITICAL Packages You've Never Heard Of

The Anthropic SDK Depends on 2 CRITICAL Packages You've Never Heard Of

Comments
2 min read
Anatomy of a GitHub Actions Supply Chain Attack Targeting MCP Repos
Cover image for Anatomy of a GitHub Actions Supply Chain Attack Targeting MCP Repos

Anatomy of a GitHub Actions Supply Chain Attack Targeting MCP Repos

Comments
7 min read
Software Supply Chain Security After Axios

Software Supply Chain Security After Axios

Comments
6 min read
Paste your package.json, see which dependencies are CRITICAL supply chain risks

Paste your package.json, see which dependencies are CRITICAL supply chain risks

Comments
2 min read
Axios Was Compromised. Here's What It Means for Your Repo.
Cover image for Axios Was Compromised. Here's What It Means for Your Repo.

Axios Was Compromised. Here's What It Means for Your Repo.

Comments
3 min read
I audited 10 common npm packages. Three came back CRITICAL. One was just attacked last week.

I audited 10 common npm packages. Three came back CRITICAL. One was just attacked last week.

Comments
3 min read
I built a Claude Code plugin that blocks compromised packages before installation
Cover image for I built a Claude Code plugin that blocks compromised packages before installation

I built a Claude Code plugin that blocks compromised packages before installation

Comments
2 min read
The Security Scanner Was the Attack Vector — How Supply Chain Attacks Hit AI Agents Differently

The Security Scanner Was the Attack Vector — How Supply Chain Attacks Hit AI Agents Differently

Comments 2
4 min read
What the Axios npm Compromise Means for MCP Server Maintainers

What the Axios npm Compromise Means for MCP Server Maintainers

Comments
4 min read
The Full-Stack Factory: How Digital Architectures are Re-Engineering the Textile Supply Chain

The Full-Stack Factory: How Digital Architectures are Re-Engineering the Textile Supply Chain

Comments
5 min read
Mercor AI Data Breach: Supply Chain Attack via LiteLLM Package Compromise

Mercor AI Data Breach: Supply Chain Attack via LiteLLM Package Compromise

Comments
8 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.