Dependency Surface Area 최소화를 통한 AI Supply Chain 리스크 제거
The Hidden Supply Chain Risk in Your `pip install`
The Hidden Supply Chain Risk in Your `pip install`
Why I'm leaving GitHub for Forgejo
The 20-Minute Compromise: CI/CD Audit Guide for the TanStack Supply Chain Attack
Win11 Zero-Days, npm Supply Chain, & AI Agent Security Threats
6분 내 10개 패키지 감염시킨 CI/CD 기반 자가 전파형 공급망 공격
pull_request_target 권한 허점을 이용한 Cache Poisoning 공격 및 공급망 침해
Checkmarx tackles another TeamPCP intrusion as Jenkins plugin sabotaged
Pipelock Agent Egress Control: the missing CI primitive for AI agents
How GitHub Is Securing Agentic Workflows in Modern CI CD Systems
Leading Open Source Author Calls for Verification over Trust in Software Supply Chains
The never-ending supply chain attacks worm into SAP npm packages, other dev tools
You've probably never heard of these npm packages. They're in your production app.
Google's fix for critical Gemini CLI bug might break your CI/CD pipelines
If Your Security Scanner Can't See Attack Chains, You're Flying Blind
Ongoing supply-chain attack 'explicitly targeting' security, dev tools
Supply Chain Attack 방어를 위한 Release Cooldown 전략 및 의존성 Pinning 설계
Bitwarden CLI Compromised: What Developers Need to Know About the Ongoing Checkmarx Supply Chain Attack
AgentGraph Update
How Attackers Turned Trivy Into a Weapon Against Cisco
12 Steps to Secure GitHub Actions After the Trivy Attack