#supply-chain-security
Loot, blog posts and adjacent themes connected to this topic. Follow the tag to keep it in your orbit.
More from this topic
Related reads
npm 2FA-bypass tokens lose account powers as GitHub tightens registry security
GitHub has restricted npm granular access tokens that bypass 2FA from sensitive account, organization, and package-management actions, with …
Delay Dependabot Version PRs Before Fresh Packages Hit Your Build
GitHub now delays Dependabot version update pull requests for three days by default, giving maintainers and scanners time to catch compromis…
GitHub actions/checkout v7: Security and Breaking Changes
GitHub actions/checkout v7 blocks common pwn-request patterns. See the July 16 backport, affected workflows, breaking behavior and upgrade c…
Use GitHub Innersource Advisories before internal packages hide security fixes
GitHub Advanced Security enterprise customers can now publish private internal advisories that trigger Dependabot alerts and fixes across re…
npm v12 turns risky install behavior into explicit opt-in
npm v12 is now tagged latest, turning dependency install scripts, Git dependencies, and remote URL packages into explicit opt-in paths while…

