Skip to main content
Tag

Supply chain security

9 articles on supply chain security.

← All blog posts
GitHub Actions OIDC: Secure Cloud Deployments
Supply Chain2026-08-24

GitHub Actions OIDC: Secure Cloud Deployments

Replace long-lived cloud secrets with GitHub Actions OIDC while constraining claims, permissions, environments, reusable workflows, and incident response.

4 min read
Sigstore and Cosign: Verify Container Images
Supply Chain2026-08-24

Sigstore and Cosign: Verify Container Images

Sign and verify container images with Cosign, keyless identities, transparency evidence, digest pinning, and admission policies that check the signer.

4 min read
SLSA Provenance: Verify the Software Supply Chain
Supply Chain2026-08-24

SLSA Provenance: Verify the Software Supply Chain

Use SLSA provenance to trace artifacts to source and build systems, verify expectations, improve CI controls, and respond to tampering.

4 min read
Malicious PyPI Packages: Detect Supply-Chain Attacks
Supply Chain2026-08-24

Malicious PyPI Packages: Detect Supply-Chain Attacks

Detect malicious PyPI packages through provenance, dependency controls, install behavior, network telemetry, hashes, and a Python incident playbook.

3 min read
GitHub Actions and CI/CD Pipeline Compromise: A Growing Supply Chain Attack Vector
Supply Chain2026-08-05

GitHub Actions and CI/CD Pipeline Compromise: A Growing Supply Chain Attack Vector

CI/CD pipeline compromises keep recurring across GitHub Actions ecosystems. Learn the detection signals, hardening steps, and enrichment workflow security teams need.

6 min read
MCP Security Risks: Tool Poisoning, Prompt Injection, and the New AI Agent Attack Surface
AI & ML2026-05-09

MCP Security Risks: Tool Poisoning, Prompt Injection, and the New AI Agent Attack Surface

Model Context Protocol integrations give agents access to tools, files, and services. That power creates new risks: tool poisoning, prompt injection, overbroad permissions, and untrusted server abuse.

10 min read
Malicious npm Packages: Detecting Open-Source Supply Chain Compromise
Supply Chain2026-05-03

Malicious npm Packages: Detecting Open-Source Supply Chain Compromise

Malicious npm packages use typosquatting, dependency confusion, install scripts, and maintainer compromise to steal secrets and backdoor builds. Learn practical detection and response.

10 min read
Supply Chain CVE Response: SBOMs, Dependency Risk, and Coordinated Vulnerability Disclosure
Supply Chain2026-04-25

Supply Chain CVE Response: SBOMs, Dependency Risk, and Coordinated Vulnerability Disclosure

Build a modern supply-chain security program: generate SBOMs, map CVEs to components, integrate EPSS and KEV, and coordinate fixes across vendors and open-source maintainers.

8 min read
Watering Hole Attacks: Compromising the Sites Your Victims Already Trust
Threat Intel2026-04-05

Watering Hole Attacks: Compromising the Sites Your Victims Already Trust

Instead of spear-phishing individuals, APTs infect websites their targets routinely visit. Learn how watering hole campaigns work and how to harden web supply chains and detection.

2 min read