NPM Supply Chain: When a Dependency Becomes an Attack Surface
Recent attacks show that the risk is no longer limited to malicious packages. It now spans CI/CD, tokens, IDEs, AI agents, and the entire software delivery process.
Read post →Notes on technology
Technical observations, lessons from projects, and ideas worth recording with a little more care.
Recent attacks show that the risk is no longer limited to malicious packages. It now spans CI/CD, tokens, IDEs, AI agents, and the entire software delivery process.
Read post →