DEV Community

# supplychain

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Twelve Trust Boundaries: A Field Guide to Supply-Chain Defense After axios@1.14.1

Twelve Trust Boundaries: A Field Guide to Supply-Chain Defense After axios@1.14.1

Comments
28 min read
Twelve Trust Boundaries: A Field Guide to Supply-Chain Defense After axios@1.14.1

Twelve Trust Boundaries: A Field Guide to Supply-Chain Defense After axios@1.14.1

Comments
28 min read
Add Real Business Trust Signals to Claude Desktop in 60 Seconds

Add Real Business Trust Signals to Claude Desktop in 60 Seconds

Comments
2 min read
Add Trust Scoring to Your CI Pipeline in 5 Minutes

Add Trust Scoring to Your CI Pipeline in 5 Minutes

Comments
3 min read
AGENTS.md moved AI performance up a model tier. Package trust needs the same.

AGENTS.md moved AI performance up a model tier. Package trust needs the same.

Comments
2 min read
Twelve Trust Boundaries: A Field Guide to Supply-Chain Defense After axios@1.14.1

Twelve Trust Boundaries: A Field Guide to Supply-Chain Defense After axios@1.14.1

1
Comments
29 min read
How to Choose a PCB Manufacturer – A Practical Guide for Hardware Engineers

How to Choose a PCB Manufacturer – A Practical Guide for Hardware Engineers

Comments
4 min read
MCPwn Is Live. We Scanned the Supply Chains of 14 MCP Servers. Here's What We Found.

MCPwn Is Live. We Scanned the Supply Chains of 14 MCP Servers. Here's What We Found.

Comments
5 min read
One Year of Liberation Day: What the Tariff Rollout Actually Revealed About AI Infrastructure

One Year of Liberation Day: What the Tariff Rollout Actually Revealed About AI Infrastructure

Comments
8 min read
161 verified AI package hallucinations across 8.5M indexed — open dataset

161 verified AI package hallucinations across 8.5M indexed — open dataset

Comments
4 min read
Proof-of-Commitment Internals: How the Scoring Algorithm Works

Proof-of-Commitment Internals: How the Scoring Algorithm Works

1
Comments
6 min read
Four MCP packages, four ways the supply chain shifted in two weeks of npm monitoring

Four MCP packages, four ways the supply chain shifted in two weeks of npm monitoring

Comments
7 min read
Slopsquatting in Python: What 205,474 Hallucinated Package Names Mean for Your Supply Chain

Slopsquatting in Python: What 205,474 Hallucinated Package Names Mean for Your Supply Chain

Comments
8 min read
I built chainscope: reading supply chain attacks across 6 surfaces, one slide at a time

I built chainscope: reading supply chain attacks across 6 surfaces, one slide at a time

Comments
7 min read
SLSA Provenance Hands-on: Generate with GitHub Actions, Verify with slsa-verifier

SLSA Provenance Hands-on: Generate with GitHub Actions, Verify with slsa-verifier

Comments
11 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.