Software Supply-Chain Security
The code you did not write is still your problem. Attacks on npm and package registries, keeping dependency trees small, and what regulation like the Cyber Resilience Act means for open source.
8 posts on this topic, newest first.
A Rogue Registry in My Own Backyard: Anatomy of a Two-Line Supply Chain Attack
Let the ORM fight begin!
Your build pipeline is not your trust boundary
Less Dependencies, Less Problems: How to keep node.js Package Footprint Minimal
Facing the Shai-Hulud Worm: Where the Hell is Easystreet?
Building a CLI for the Ecosyste.ms API
Open-Source & Cyber Resilience Act - Differing opinions aside
A piece on “OpSec” and Events/Hackathons/Barcamps