supply-chain-security

Tag

Cards List
#supply-chain-security

Dependabot version updates introduce default package cooldown

Hacker News Top · 2026-07-14 Cached

Dependabot now waits three days before opening version update PRs to reduce risk of supply chain attacks. Security updates remain immediate.

0 favorites 0 likes
#supply-chain-security

Config Files That Run Code: Supply Chain Security Blindspot

Hacker News Top · 2026-06-08 Cached

Config files for IDEs, AI coding agents, and package managers can execute code automatically, creating a supply chain security blindspot. The article details the Miasma worm attack that uses such config files to drop malware, and provides examples of injection vectors.

0 favorites 0 likes
#supply-chain-security

Reproducible Builds in May 2026

Lobsters Hottest · 2026-06-04 Cached

The May 2026 Reproducible Builds report highlights a major Debian policy change requiring all packages to be reproducible for inclusion in the 'forky' release, along with news about a 2026 summit in Gothenburg, a new rebuilderd version, and other project updates.

0 favorites 0 likes
#supply-chain-security

Cooldown Support for Ruby Bundler

Hacker News Top · 2026-06-03 Cached

Bundler 4.0.13 introduces a cooldown feature that blocks resolution to gems published less than N days ago, mitigating supply-chain attacks. It is opt-in and configurable per source, setting, or command-line flag.

0 favorites 0 likes
#supply-chain-security

I trust-scored 171 open-source AI agents — most can't prove their supply chain

Reddit r/AI_Agents · 2026-05-29

A developer created an independent trust registry for 171 open-source AI agents, scoring them on verifiable trust signals like supply chain security and maintenance, finding that only three agents achieved a Grade A rating while many popular agents lacked basic verification.

0 favorites 0 likes
#supply-chain-security

Staged publishing and new install-time controls for npm

Hacker News Top · 2026-05-22 Cached

npm introduces staged publishing, requiring human approval via 2FA for package releases, and new `--allow-*` flags (file, remote, directory) to control install sources, improving supply-chain security in npm CLI 11.15.0.

0 favorites 0 likes
#supply-chain-security

Dependency cooldowns are unfair; we should use phased rollouts instead

Lobsters Hottest · 2026-05-21 Cached

The article argues that dependency cooldowns unfairly burden developers in earlier time zones and proposes using deterministic phased rollouts based on project identifiers to distribute adoption more equitably.

0 favorites 0 likes
#supply-chain-security

The npm/Docker/PyPI supply chain security pattern is repeating with MCP, and we are at the 2015 moment

Reddit r/AI_Agents · 2026-05-17

The article warns that the MCP ecosystem is repeating the same supply chain security pattern seen in npm, Docker, and PyPI, with minimal vetting and growing risks. It highlights that a scan of 500 Smithery servers found 18.8% with security issues and that existing security tooling cannot handle malicious agent instructions, and introduces a new static scanner called bawbel.

0 favorites 0 likes
#supply-chain-security

Popular Go library fsnotify raises supply chain alarms after maintainer access changes

Lobsters Hottest · 2026-05-12

The popular Go library fsnotify has raised supply chain security concerns following changes to maintainer access.

0 favorites 0 likes
#supply-chain-security

Kettle: Attested builds for verifiable software provenance

Lobsters Hottest · 2026-05-12 Cached

This paper introduces Kettle, an attested build system that generates cryptographically verifiable software provenance using Trusted Execution Environments (TEEs). It aims to eliminate the build infrastructure and operators from the trust surface by binding provenance documents directly to hardware-signed attestation reports.

0 favorites 0 likes
#supply-chain-security

Show HN: Safe-install – safer NPM installs with trusted build dependencies

Hacker News Top · 2026-05-12

A new npm package called safe-install is introduced to enhance supply chain security by allowing developers to disable install scripts by default and block exotic sub-dependencies, addressing ongoing vulnerabilities.

0 favorites 0 likes
#supply-chain-security

@RhysSullivan: just enabled a minimum age on npm package installs for my machine, should've done this sooner but if you haven't either…

X AI KOLs Following · 2026-05-11

A developer shares a tip to configure a minimum release age for package installs to mitigate supply-chain attacks.

0 favorites 0 likes
#supply-chain-security

What LiteLLM’s Security Breach Teaches AI Agent Engineering Teams

Reddit r/AI_Agents · 2026-05-10

The article discusses the security breach of LiteLLM and its implications for AI agent engineering teams, highlighting the need for improved supply chain security and infrastructure governance.

0 favorites 0 likes
← Back to home

Submit Feedback