Tag: Software Supply Chain Security
Why Software Supply Chain Security Is Moving to the Gate
March 2026: malicious versions of axios get published directly to npm. May 2026: attackers forge valid provenance for 42 TanStack packages on npm, with 84 malicious versions shipped before detection. August 2026: ...
GitHub Gives Enterprises a Full Count of Who Holds the Keys
GitHub Enterprise Cloud now lets organizations export a full inventory of credentials, helping security teams identify stale, overprivileged and forgotten access across users, apps and automation ...
Cycode Extends DevSecOps Reach to Software Packages Developers Download
Cycode is adding workstation-level protection to stop developers and AI coding agents from downloading malicious or insufficiently vetted software packages ...
Why Shift Left is Dead
AI-driven development is exposing risks before code is written, forcing security teams to move beyond shift-left and govern agents, prompts, tools and data across the entire development lifecycle ...
GitHub Widens the Door on Advanced Security Trials
GitHub raised its self-serve Advanced Security trial cap from 100 to 300 licenses, letting more mid-size Enterprise Cloud orgs test for free ...
Broadcom Launches TrueSource Service to Secure Spring Framework
Broadcom launches TrueSource Trusted Artifacts to provide hardened Spring dependencies, secure open source packages and automated vulnerability remediation ...
Why Cryptographic Inventory Is the First Step Toward Quantum Readiness
Post-quantum readiness starts with visibility. DevOps teams need a continuous cryptographic inventory to map algorithms, keys, certificates, libraries, infrastructure and third-party dependencies before PQC migration begins ...
The Agent Proposes, the Pipeline Disposes: Controls for AI-Authored Change
When agents write code and open pull requests faster than humans can read them, ‘the diff looked fine’ stops being a control. The durable controls live outside the agent’s reasoning loop ...
Shift Left Security: 4 Automated Security Gates in GitHub Actions
Learn how to add four automated security gates to GitHub Actions using npm audit, Snyk, Trivy, CodeQL and OWASP ZAP—without an enterprise licence ...
CISA’s 2026 SBOM Guidance Adds Hash Requirements and AI Coverage
CISA’s updated 2026 SBOM minimum elements expand software transparency requirements to AI, SaaS and open source while adding hashes, licenses and stronger validation ...
GitHub and PyPI Bet On Time to Slow Down Software Supply Chain Attacks
GitHub and PyPI are using time as a security control, delaying dependency updates and locking older releases against new file uploads ...
Signed, Attested, and Malicious: The Software Supply Chain Has a Deepfake Problem
A developer pulls a package from a reliable repo. It is signed, has provenance, and has been scanned. And then…it contains malware. That is no longer hypothetical. When the Miasma worm tore ...

