home.social

#supply-chain-security — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #supply-chain-security, aggregated by home.social.

fetched live
  1. We hope you enjoyed @glaubinix talk on the malware filtering features in Composer 2.10 at phpday. Try them out on latest snapshots today. Appreciate early feedback! Proud to sponsor @phpday in Verona, Italy!

    Slides at glaubinix.github.io/talks/2026

    #php #phpc #phpday #composerphp #supplychainsecurity #malware

  2. Dear opensource developers,

    I added an "adoption" list to the repro-env README, if you publish pre-compiled binaries and you successfully adopted it to allow anyone to reproduce them from source code to prove the absense of a build server compromise, you are very welcome to add yourself to the list. 😺

    github.com/kpcyrd/repro-env#ad

    #reproducible #reproduciblebuilds #supplychainsecurity #rust

  3. TeamPCP claims it breached Mistral AI while the company confirms impact from the TanStack supply chain attack involving malicious NPM and PyPI packages.

    Mistral says there’s currently no evidence of an internal infrastructure breach.

    technadu.com/teampcp-claims-mi

    #Cybersecurity #SupplyChainSecurity #AI #Infosec

  4. Debian 14 Forky is mandating bit-for-bit identical builds to stop supply chain attacks. Discover how this shifts trust from servers to auditable source code.

    More details here: ostechnix.com/debian-linux-rep

    #Debian14 #DebianForky #ReproducibleBuilds #Security #Linux #Packages #SupplyChainSecurity

  5. Open source malicious package detections went from 20,000 a day to 100,000 in twelve months🤯

    Aikido Security has been watching and building for exactly this.

    Proud to have them as a Gold Sponsor for this year!

    aikido.dev/?utm_source=appsec-

    #AppSec #SupplyChainSecurity

  6. You trust your dependencies? That’s the risk. From #Log4Shell to self-replicating worms, attacks don’t hit your code first — they hit your supply chain, often via packages.

    @MohammadAliEN explains what to watch: javapro.io/2026/04/23/the-whis

    #AppSec #Java #SupplyChainSecurity

  7. Palantir Technologies secures $300 million USDA contract to enhance U.S. farmland management and food security amid global supply chain threats and growing concerns over foreign agricultural land acquisitions, marking the company's expansion beyond defense sector into civilian government agencies.
    #YonhapInfomax #PalantirTechnologies #USDA #FoodSecurity #FarmlandManagement #SupplyChainSecurity #Economics #FinancialMarkets #Banking #Securities #Bonds #StockMarket
    en.infomaxai.com/news/articleV

  8. 🚨 Emergency DevSec Station drop.
    There's an active npm supply chain attack happening right now. Compromised packages are stealing SSH keys, AWS credentials, GitHub tokens, browser passwords, and crypto wallets on install. Then using your publish token to infect every package you maintain.
    One command can protect you immediately: npm config set ignore-scripts true
    Do it today, please. Tell your team. Watch the full 60 seconds.
    #AppSec #SupplyChainSecurity #DevSecOps #SecureCoding #npm

  9. New article: Using Forgejo git mirrors and Nix flakes to build security-critical software from self-hosted, pinned sources.

    With over 454,000 malicious packages identified in 2025, self-replicating npm worms, and AI-powered attack campaigns, supply chain security is no longer an option for self-hosters.

    The post outlines an approach that effectively mitigates risks and highlights its limitations.

    blog.networld.to/git-mirrors-a

    #NixOS #Forgejo #SupplyChainSecurity #SelfHosting #InfoSec

  10. I'm on Fallthrough: Supply Chain Reaction

    Announcing my appearance as a guest co-host on Fallthrough, talking about supply chain security, AI, Claude Mythos, and many more topics.

    fed.brid.gy/r/https://www.jvt.