Tag: Repository Security
GitHub Separates Who Writes Code From Who Runs Your CI
GitHub’s new workflow execution protections let teams control who and what can trigger Actions workflows, reducing CI/CD attack paths and tightening pipeline security ...
More JFrog Artifactory Bugs Are Under Attack, and All Three Have Patches
Attackers are actively exploiting three JFrog Artifactory flaws, exposing how slow patching can turn artifact repositories into software supply chain attack paths ...
GitLab’s Critical Patch Closes a Path Traversal Flaw Attackers Are Already Probing
GitLab patches two critical flaws, including a CVSS 10.0 unauthenticated file-read vulnerability, putting self-managed instances under urgent pressure to upgrade ...
GitHub Widens the Door on Advanced Security Trials
GitHub raised its self-serve Advanced Security trial cap from 100 to 300 licenses, letting more mid-size Enterprise Cloud orgs test for free ...
xAI Open-Sources Grok Build Coding Agent After Cloud Upload Exposes SSH Keys, Repos
xAI has published the full source code for Grok Build, its terminal-based AI coding agent, on GitHub under an Apache 2.0 license. The release lands three days after a security researcher showed ...
Fake Stars in GitHub a Growing Security Threat, Analysis Finds
There was a surge of inauthentic stars on code repositories in 2024, ramping up the threat of software supply chain attacks ...
npm is Scam-Spam Cesspool ¦ Google in Microsoft Antitrust Thrust
In this week’s #TheLongView: The npm registry suffers spam infestation, and Microsoft makes Google sad ...

