Comment on Two different attackers poisoned popular open source tools - and showed us the future of supply chain compromise

14th_cylon@lemmy.zip ⁨1⁩ ⁨week⁩ ago

First, attackers hit Trivy, a vulnerability scanner with more than 100,000 users and contributors that is embedded in thousands of CI/CD pipelines. Up next: Axios, an open-source JavaScript library that has about 100 million weekly downloads and runs in 80 percent of cloud and code environments.

source
Sort:hotnewtop