Skip to main content
Tag

supply chain security

9 articles on supply chain security.

← All blog posts
GitHub Actions OIDC: Secure Cloud Deployments
CloudAug 24, 2026

GitHub Actions OIDC: Secure Cloud Deployments

Replace long-lived cloud secrets with GitHub Actions OIDC while constraining claims, permissions, environments, reusable workflows, and incident response.

4 min read
Sigstore and Cosign: Verify Container Images
AI & MLAug 24, 2026

Sigstore and Cosign: Verify Container Images

Sign and verify container images with Cosign, keyless identities, transparency evidence, digest pinning, and admission policies that check the signer.

4 min read
SLSA Provenance: Verify the Software Supply Chain
Supply ChainAug 24, 2026

SLSA Provenance: Verify the Software Supply Chain

Use SLSA provenance to trace artifacts to source and build systems, verify expectations, improve CI controls, and respond to tampering.

4 min read
Malicious PyPI Packages: Detect Supply-Chain Attacks
Supply ChainAug 24, 2026

Malicious PyPI Packages: Detect Supply-Chain Attacks

Detect malicious PyPI packages through provenance, dependency controls, install behavior, network telemetry, hashes, and a Python incident playbook.

3 min read
GitHub Actions and CI/CD Pipeline Compromise: A Growing Supply Chain Attack Vector
Supply ChainAug 5, 2026

GitHub Actions and CI/CD Pipeline Compromise: A Growing Supply Chain Attack Vector

CI/CD pipeline compromises keep recurring across GitHub Actions ecosystems. Learn the detection signals, hardening steps, and enrichment workflow security teams need.

6 min read
MCP Security Risks: Tool Poisoning, Prompt Injection, and the New AI Agent Attack Surface
AI & MLMay 9, 2026

MCP Security Risks: Tool Poisoning, Prompt Injection, and the New AI Agent Attack Surface

Model Context Protocol integrations give agents access to tools, files, and services. That power creates new risks: tool poisoning, prompt injection, overbroad permissions, and untrusted server abuse.

10 min read
Malicious npm Packages: Detecting Open-Source Supply Chain Compromise
Supply ChainMay 3, 2026

Malicious npm Packages: Detecting Open-Source Supply Chain Compromise

Malicious npm packages use typosquatting, dependency confusion, install scripts, and maintainer compromise to steal secrets and backdoor builds. Learn practical detection and response.

10 min read
Supply Chain CVE Response: SBOMs, Dependency Risk, and Coordinated Vulnerability Disclosure
Supply ChainApr 25, 2026

Supply Chain CVE Response: SBOMs, Dependency Risk, and Coordinated Vulnerability Disclosure

Build a modern supply-chain security program: generate SBOMs, map CVEs to components, integrate EPSS and KEV, and coordinate fixes across vendors and open-source maintainers.

9 min read
Watering Hole Attacks: Compromising the Sites Your Victims Already Trust
Threat IntelApr 5, 2026

Watering Hole Attacks: Compromising the Sites Your Victims Already Trust

Instead of spear-phishing individuals, APTs infect websites their targets routinely visit. Learn how watering hole campaigns work and how to harden web supply chains and detection.

2 min read