🦞🌯 Lobster Roll

Thread

How Go Mitigates Supply Chain Attacks (go.dev)

Stories related to "How Go Mitigates Supply Chain Attacks" across the full archive.

How Go Mitigates Supply Chain Attacks (go.dev)
Supply Chain Attacks and Secure Software Updates (dev.to)
WordPress 5.2: Mitigating Supply-Chain Attacks Against 33% of the Internet (paragonie.com)
Backstabber's Knife Collection: A Review of Open Source Software Supply Chain Attacks (arxiv.org)
Linux marketplaces vulnerable to RCE and supply chain attacks (positive.security)
GitHub brings supply chain security features to the Go community (github.blog)
Making Rust supply chain attacks harder with Cackle (davidlattimore.github.io)
Open Source Supply Chain Security at Google (youtube.com)
Supply chain attacks and the many different ways I've backdoored your dependencies (kerkour.com)
Vulnerabilities in CocoaPods Open the Door to Supply Chain Attacks Against Thousands of iOS and MacOS Applications (evasec.io)
Supply chain attacks and backdoored dependencies (kerkour.com)
Ask HN: Pragmatic way to avoid supply chain attacks as a developer
In the usual course of writing software, it's common to install huge dependency chains (npm, pypi), and any vulnerable package could spell doom. There's some nasty stuff out there, like https://pytorch.org/blog/compromised-nightly-dependency/ which uploaded people&...
Israel's Pager Attacks and Supply Chain Vulnerabilities (schneier.com)
Israel's Pager Attacks and Supply Chain Vulnerabilities (schneier.com)
Practical countermeasures against supply chain attacks (kerkour.com)
Socket secures $40M to combat next-generation software supply chain attacks (socket.dev)
Supply Chain Attacks Targeting LLM Application Developers: The Hidden Dangers Of (socket.dev)
Hacking Fortune 500 Companies via Supply Chain Attacks (landh.tech)
It's only a matter of time before LLMs jump start supply-chain attacks (theregister.com)
API Supply Chain Attacks – The Sky's the Limit (salt.security)
Go Supply Chain Attack: Malicious Package Exploits Go Module (socket.dev)
Countermeasures v.s supply chain attacks, Where Rust can be UNSAFE in practice (kerkour.com)
The Risks of SaaS Supply Chain Attacks and How to Stay Secure (reco.ai)
Supply Chain Attacks on Linux Distributions (fenrisk.com)
Supply Chain Attacks on Linux Distributions – Fedora Pagure (fenrisk.com)
Ask HN: How are you protecting against supply chain attacks?
How are companies protecting against the constant risk of supply chain attacks? Everything from a rogue package reading API keys on a dev machine to the XZ backdoor enabling remote execution on any server with exposed ssh.<p>It&#x27;s not a new problem. There are many companies trying to solve it. A...
Show HN: Scharf – Find and protect ur GitHub Actions from supply-chain attacks (github.com)
Welcome to &quot;Scharf&quot;, a blazing-fast security scanner for hardening third-party GitHub actions with mutable references. Using mutable references (version tags, main&#x2F;master&#x2F;dev etc.) is a security vulnerability that can result in supply-chain attacks.<p>The recent `tj-actions&#x2F;...
Done with GitHub Actions Supply Chain Attacks (huijzer.xyz)
Done with GitHub Actions Supply Chain Attacks (huijzer.xyz)
Slopsquatting: AI Hallucinations Fuel New Class of Supply Chain Attacks (socket.dev)