» Tag
dependencies
8 postsMalicious Rust Crate Arrayref Executes a Build-Time Payload
A compromised release of the arrayref crate runs a malicious payload at build time, raising security concerns for developers.
Claude Code Skills for Safe PHP and JS Package Updates
Enhance the safety of PHP and JS package updates with Claude code skills.
Slopsquatting: Your Coding Agent Is a Supply-Chain Attack Vector
Slopsquatting is a supply-chain attack emerging from AI coding agents. Learn how LineageLens Trellis mitigates this risk.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comAI Agent Fixes 98% of Vulnerable Dependencies in One Run
An AI agent achieved 98% vulnerability fixes in a Maven project, showcasing advancements in automated dependency management.
The AI Supply Chain: The Next Evolution of Third Party Risk
AI supply chain risk is evolving beyond traditional third-party risk management.
Safer-dependencies: A Security Layer for Claude Code
Safer-dependencies is a security layer for Claude Code that audits package dependencies.
Security Mining Report: Challenges in Val Town
Exploring security challenges in Val Town and new threats in modern web applications.
How TypeScript Developers Can Avoid Malicious Package Attacks
Learn how TypeScript developers can protect against malicious npm package attacks.