Meta tags:
description= supplychain content on DEV Community;
keywords= software development, engineering, supplychain;
Headings (most frequently used words):
the, and, is, chain, supply, that, in, you, why, security, signing, cve, 2026, repository, on, everything, an, two, control, not, jfrog, artifactory, github, actions, problem, supplychain, posts, dev, community, beyond, package, name, following, call, hard, part, of, what, ed25519, actually, proves, about, test, result, oc, mirror, 75939, signature, check, runs, wrong, order, nexus, manager, 81, 550, title, matches, 33, 844, fingerprints, artefact, pipeline, depends, three, merged, prs, mcp, scanner, review, found, my, bug, more, container, image, provenance, half, rotating, credentials, revoking, them, revocation, unit, decides, whether, can, flaws, one, how, was, pushed, to, admin, 60004, code, injection, through, gitea, diffpatch, api, forge, holds, removed, node, 20, find, every, node20, action, still, run, browser, extensions, are, enterprise, user, hygiene, risk, pinning, oidc, least, privilege, tokens, when, artifact, target, software, chokepoint, brevo, cloudflare, worker, rewrote, marketing, platform, flight, yarn, lock, may, force, be, with, trending, guides, resources,
Text of the page (most frequently used words):
the (43), and (19), supplychain (17), follow (16), min (15), read (15), comment (15), comments (15), add (14), chain (13), #security (13), dev (12), oct (12), onaeiuspkz (12), you (11), supply (10), jfrog (9), artifactory (9), that (8), signing (7), software (6), your (6), not (6), two (6), kozhevniko (6), with (5), 2026 (5), image (5), control (5), github (5), actions (5), one (5), artifact (5), admin (5), why (5), repository (5), community (4), code (4), about (4), what (4), actually (4), flaws (4), them (4), can (4), tokens (4), when (4), three (4), problem (4), devops (4), cve (4), everything (4), create (3), container (3), provenance (3), half (3), rotating (3), credentials (3), revoking (3), revocation (3), unit (3), decides (3), whether (3), review (3), npm (3), yarn (3), lock (3), may (3), force (3), how (3), was (3), pushed (3), runs (3), target (3), are (3), for (3), pipeline (3), posts (3), reaction (3), sep (3), anton (3), golub (3), yutianle (3), starkman (3), jeffrey (3), node (3), daily (3), gitea (3), ntctech (3), mcp (3), edison (3), flores (3), anthony (3), garces (3), jj1423 (3), menu (3), account (2), log (2), open (2), source (2), base (2), wordpress (2), will (2), never (2), repositories (2), key (2), ability (2), sort (2), top (2), latest (2), relevant (2), sign (2), brevo (2), cloudflare (2), worker (2), rewrote (2), marketing (2), platform (2), flight (2), chokepoint (2), githubactions (2), cicd (2), risk (2), pinning (2), oidc (2), least (2), privilege (2), browser (2), extensions (2), enterprise (2), user (2), hygiene (2), removed (2), find (2), every (2), node20 (2), action (2), still (2), run (2), 60004 (2), injection (2), through (2), diffpatch (2), api (2), forge (2), holds (2), merged (2), prs (2), scanner (2), found (2), bug (2), more (2), nexus (2), manager (2), 550 (2), title (2), matches (2), 844 (2), fingerprints (2), artefact (2), depends (2), mirror (2), 75939 (2), signature (2), check (2), wrong (2), order (2), ed25519 (2), proves (2), test (2), result (2), beyond (2), package (2), name (2), following (2), call (2), hard (2), part (2), search (2), place, where, coders, share, stay, date, grow, their, careers, made, love, 2016, ruby, rails, built, powers, other, inclusive, communities, forem, terms, use, privacy, policy, conduct, mlh, shop, free, postgres, database, contact, showcase, organization, accounts, advertise, help, education, tracks, videos, challenges, home, space, discuss, keep, development, manage, career, aliexpress, wasn, beaming, ultrasonic, audio, shoppers, ran, harder, block, jenkins, controller, compromise, event, lessons, from, plugin, vendor, now, nobody, coming, clean, popular, projects, sha, pin, time, but, docker, images, only, verification, layer, below, admission, dashboard, warn, these, saml, forgery, bugs, pypi, stops, accepting, late, file, uploads, releases, older, than, days, print, servers, measuring, overlooked, attack, surfaces, gnu, strip, backdoor, case, see, audit, won, save, first, hour, alert, default, join, let, attackers, mint, stop, slopsquatting, gate, better, prompt, verdaccio, 336, hosts, private, registries, they, hand, out, authentication, bypass, empty, becomes, token, rapidfort, points, its, hardened, business, production, has, 684, cves, choke, coding, agents, ways, break, thing, detection, give, trust, anchors, incident, response, compromised, build, inside, litellm, hack, 153gb, 433, 909, files, 488, organizations, trending, guides, resources, javascript, clickfix, cdn, vulnerabilitymanagement, enterprisepolicy, extensionmanagement, browsersecurity, reactions, codeinjection, architecture, containers, python, exposure, disconnected, pgp, openshift, evidence, vulnerabilities, right, left, post, hide, close, powered, algolia, navigation, skip, content,
Text of the page (random words):
supplychain dev community skip to content navigation menu search powered by algolia search log in create account dev community close supplychain follow hide create post posts left menu sign in for the ability to sort posts by relevant latest or top right menu beyond the package name why following the call is the hard part of supply chain security jj1423 jj1423 jj1423 follow oct 5 beyond the package name why following the call is the hard part of supply chain security vulnerabilities security supplychain ai comments add comment 3 min read what ed25519 signing actually proves about a test result anthony garces anthony garces anthony garces follow oct 5 what ed25519 signing actually proves about a test result evidence signing supplychain comments add comment 6 min read oc mirror cve 2026 75939 a signature check that runs in the wrong order onaeiuspkz onaeiuspkz onaeiuspkz follow oct 5 oc mirror cve 2026 75939 a signature check that runs in the wrong order openshift supplychain pgp disconnected comments add comment 2 min read nexus repository manager 81 550 title matches and 33 844 fingerprints on the artefact pipeline everything depends on onaeiuspkz onaeiuspkz onaeiuspkz follow oct 4 nexus repository manager 81 550 title matches and 33 844 fingerprints on the artefact pipeline everything depends on exposure supplychain comments add comment 2 min read three merged prs in an mcp security scanner the review that found my bug and two more edison flores edison flores edison flores follow oct 3 three merged prs in an mcp security scanner the review that found my bug and two more mcp security supplychain python comments add comment 4 min read container image provenance signing is half the control kozhevniko kozhevniko kozhevniko follow oct 3 container image provenance signing is half the control security containers supplychain comments add comment 2 min read rotating credentials is not revoking them the revocation unit decides whether you can ntctech ntctech ntctech follow oct 2 rotating credentials is not revoking them the revocation unit decides whether you can security devops architecture supplychain comments add comment 8 min read two flaws one chain how jfrog artifactory was pushed to admin kozhevniko kozhevniko kozhevniko follow oct 1 two flaws one chain how jfrog artifactory was pushed to admin security jfrog artifactory supplychain comments add comment 4 min read cve 2026 60004 code injection through the gitea diffpatch api and why a forge holds everything onaeiuspkz onaeiuspkz onaeiuspkz follow oct 1 cve 2026 60004 code injection through the gitea diffpatch api and why a forge holds everything gitea supplychain codeinjection comments add comment 2 min read github actions removed node 20 find every node20 action you still run devops daily devops daily devops daily follow oct 1 github actions removed node 20 find every node20 action you still run cicd githubactions node supplychain 4 reactions comments add comment 14 min read browser extensions are an enterprise control problem not a user hygiene problem jeffrey jeffrey jeffrey follow oct 1 browser extensions are an enterprise control problem not a user hygiene problem browsersecurity extensionmanagement enterprisepolicy supplychain 1 reaction comments add comment 4 min read github actions supply chain risk pinning oidc and least privilege tokens onaeiuspkz onaeiuspkz onaeiuspkz follow oct 1 github actions supply chain risk pinning oidc and least privilege tokens supplychain cicd githubactions 1 reaction comments add comment 2 min read when the artifact repository is the target jfrog artifactory and the software supply chain chokepoint starkman starkman starkman follow sep 30 when the artifact repository is the target jfrog artifactory and the software supply chain chokepoint security supplychain vulnerabilitymanagement comments add comment 3 min read brevo a cloudflare worker that rewrote a marketing platform in flight yutianle yutianle yutianle follow sep 30 brevo a cloudflare worker that rewrote a marketing platform in flight supplychain cdn wordpress clickfix comments add comment 2 min read yarn lock may the force be with you anton golub anton golub anton golub follow sep 29 yarn lock may the force be with you javascript security npm supplychain 1 reaction comments 1 comment 14 min read sign in for the ability to sort posts by relevant latest or top trending guides resources inside the litellm hack 153gb 433 909 files 2 488 organizations artifact repositories are trust anchors incident response for a compromised build pipeline three ai coding agents three ways to break them and one thing detection will never give you when the artifact repository is the target jfrog artifactory and the software supply chain choke why your base image has 1 684 cves rapidfort points its hardened open source business at what actually runs in production the jfrog artifactory authentication bypass when an empty signing key becomes an admin token two flaws one chain how jfrog artifactory was pushed to admin yarn lock may the force be with you verdaccio on 3 336 hosts private npm registries and the tokens they hand out stop slopsquatting with a ci gate not a better prompt the default join key that let attackers mint admin tokens on jfrog artifactory npm audit won t save you in the first hour of a supply chain alert the gnu strip backdoor is the case ai code review can t see print servers and artifact repositories measuring two overlooked attack surfaces pypi stops accepting late file uploads to releases older than 14 days your wordpress dashboard will never warn you about these saml forgery bugs rotating credentials is not revoking them the revocation unit decides whether you can image verification one layer below admission popular projects sha pin github actions 67 6 of the time but docker base images only 7 6 container image provenance signing is half the control nobody s coming to clean your supply chain your vendor s security is now your security jenkins controller compromise is a supply chain event lessons from 20 plugin flaws aliexpress wasn t beaming ultrasonic audio at shoppers what it actually ran is harder to block dev community a space to discuss and keep up software development and manage your software career home dev challenges dev videos dev education tracks dev help advertise on dev organization accounts dev showcase about contact free postgres database dev shop mlh code of conduct privacy policy terms of use built on forem the open source software that powers dev and other inclusive communities made with love and ruby on rails dev community 2016 2026 we re a place where coders share stay up to date and grow their careers log in create account
|