
All articles/Tag
Devsecops
Supply-chain attacks: package cooldowns and policy checks for npm, PyPI and NuGet
On 4 August 2026, a self-propagating worm called ChainDrop tore through npm. BleepingComputer reported more than 1,300 compromised packages with about two billion monthly downloads between them, including keyv,…
#supply-chain-security#npm#dependency-management#devsecops#ci-cd
Cutting vulnerability noise: using AI and public data to demote CVEs that don't matter
A container image scan finishes and hands back a few hundred findings. A dozen are critical. Most of the rest are base image packages with a CVE ID, a CVSS score, and no patched version anywhere in the world. The team…
#vulnerability-management#cve#patch-management#devsecops#osv