#softwaresupplychain

32 posts · Last used 14d

Back to Timeline
Pedram @psoheil@c.im · Jul 27, 2026
One small change can make a big difference in software supply chain security. PyPI has introduced a new safeguard that rejects uploads of new files to package releases older than 14 days. This helps prevent attackers who compromise a maintainer’s account or publishing pipeline from silently adding malicious files to a long-trusted package version months after it was released. While this doesn’t eliminate all supply chain threats, it significantly reduces the risk of “package poisoning” attacks against pinned dependencies and encourages immutable releases, a security best practice every ecosystem should strive for. Security isn’t about a single silver bullet, it’s about layering defenses that make attacks increasingly difficult. Could we see similar protections become the standard across other package registries like npm, NuGet, and RubyGems? https://cybersecuritynews.com/pypi-14-day-release-lock/amp/ #CyberSecurity #AppSec #SupplyChainSecurity #PyPI #Python #DevSecOps #SoftwareSecurity #OpenSource #SecureByDesign #SoftwareSupplyChain #Infosec
0
0
0
gprimola$ :idle: @giorgiolucas@techhub.social · May 05, 2026
I wonder if there's a software business model where you buy the software for the binary and the source code? The source code is not exactly open, but is available on that specific version. I'm also wondering how that would work for the software supply chain. 🤔 #Software #business #foss #oss #intelectualProperty #sourcecode #development #developers #SoftwareSupplyChain
0
3
1
anchore @anchore@mstdn.business · Apr 04, 2026
Your MCP server might be the weakest link—here's the data. @josh.bressers.name scanned 161 MCP images and found 9,000 vulns / 263 criticals. Read the breakdown and fixes: https://anchore.com/blog/analyzing-the-top-mcp-docker-containers/ #MCP #SoftwareSupplyChain #ContainerSecurity #DevSecOps
0
1
1
anchore @anchore__dup_33412@mstdn.business · Mar 08, 2026
"Source code is to build artifacts as data sets are to AI models." Kate Stewart (The Linux Foundation) explains why you can't trust your AI if you don't know what trained it. Read why the "S" in SBOM is standing for System: https://anchore.com/blog/the-s-in-sbom-is-for-system/ #SoftwareSupplyChain #SBOM
0
0
0