home.social

#software-supply-chain — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #software-supply-chain, aggregated by home.social.

fetched live
  1. #GitHub's Dependabot now waits 3 days by default before opening pull requests for new non-security dependency versions.

    The delay gives security scanners and the community more time to detect and remove malicious releases before they're integrated into projects.

    Read the full story on InfoQ 👉 bit.ly/4xeUgVY

    #DevOps #SoftwareSupplyChain #InfoQ

  2. Το είναι παντού, αλλά η ψηφιακή μας υποδομή συχνά στηρίζεται σε έναν εξουθενωμένο maintainer. 🐘🛠️

    Στο νέο άρθρο, αναλύω το "Trust-State Inversion", το GSD incident και το xz backdoor. Πώς μπορούμε να χτίσουμε μια πραγματική αγορά εμπιστοσύνης στην Ευρώπη με το επερχόμενο Cyber Resilience Act (#CRA);

    Η λύση κρύβεται στη σωστή χρηματοδότηση και τα ανοιχτά πρότυπα.

    👉 eiosifidis.blogspot.com/2026/0

  3. We have released a new version for the first time in a long while. As well as the usual software updates, it includes our experience with agent-based code generation and securing the software supply chain: python4data.science/en/26.1.0/
    #Python #DataScience #AgenticCoding #Claude #SoftwareEngineering #SoftwareSupplyChain #SupplyChain

  4. Recent attacks on TanStack, Axios, Nx Console, and DAEMON Tools reveal why code signing and software provenance prove origin, not safety. hackernoon.com/your-software-s #softwaresupplychain