#software-supply-chain — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #software-supply-chain, aggregated by home.social.
-
#GitHub's Dependabot now waits 3 days by default before opening pull requests for new non-security dependency versions.
The delay gives security scanners and the community more time to detect and remove malicious releases before they're integrated into projects.
Read the full story on InfoQ 👉 https://bit.ly/4xeUgVY
-
Το #OpenSource είναι παντού, αλλά η ψηφιακή μας υποδομή συχνά στηρίζεται σε έναν εξουθενωμένο maintainer. 🐘🛠️
Στο νέο άρθρο, αναλύω το "Trust-State Inversion", το GSD incident και το xz backdoor. Πώς μπορούμε να χτίσουμε μια πραγματική αγορά εμπιστοσύνης στην Ευρώπη με το επερχόμενο Cyber Resilience Act (#CRA);
Η λύση κρύβεται στη σωστή χρηματοδότηση και τα ανοιχτά πρότυπα.
👉 https://eiosifidis.blogspot.com/2026/07/open-source-trust-cra-ai-security.html
#Linux #Cybersecurity #openSUSE #InfoSec #SoftwareSupplyChain #TechSovereignty #Tech
-
We have released a new version for the first time in a long while. As well as the usual software updates, it includes our experience with agent-based code generation and securing the software supply chain: https://www.python4data.science/en/26.1.0/
#Python #DataScience #AgenticCoding #Claude #SoftwareEngineering #SoftwareSupplyChain #SupplyChain -
Recent attacks on TanStack, Axios, Nx Console, and DAEMON Tools reveal why code signing and software provenance prove origin, not safety. https://hackernoon.com/your-software-supply-chain-only-proves-where-code-came-from-not-whether-its-safe #softwaresupplychain