Posts on supply-chain
4 posts on supply-chain. Notes from public sources and my own test lab.
Betrayal of the Dependencies: The Art of Supply Chain Attacks and Defense
Ever wondered how a single typo in your package.json could compromise your entire infrastructure? Let's dive into the world of Software Supply Chain security and learn how to defend your fortress from the inside out.
When the Foundations Crumble: Software Supply Chain and 'Dependency Hell'
Think you're safe behind your firewall? Think again. The real threat might be that 'npm install' you just ran. Let's dive into the messy world of Software Supply Chain attacks and how they turn your trust against you.
Trusting Your Package Manager? Feeding a Trojan Horse in the Supply Chain
Think your CI/CD pipeline is safe because of a few SCA scans? Think again. We’re diving into the blind spots of package managers, from malicious logic to dependency confusion.
Whose Shoulders Are You Standing On? The Supply Chain Nightmare
You trust your code, but do you trust your dependencies? A deep dive into why shifting left also means looking at the libraries you invite into your house.