News about Supply Chain Security. Show all news
npm adds a safety pause after sensitive account changes
Software projects often depend on packages maintained by other developers. A compromised maintainer account can therefore affect far more than a single project. If an attacker uses that account to distribute a malicious update, organisations ma…
Key rotation underscores the importance of reliable updates
Reliable software updates start with the question of whether a package truly comes from the expected vendor. Digital signatures and the corresponding public keys play a central role in this. When a key is replaced as a precaution, administrator…