Topic
software-supply-chain
01
02
03
04

The Key in the Bundle
A production AWS key reached every customer browser. Here is what that exposure reveals about builds, permissions and breach evidence.
Cloud SecurityCredential ExposureIncident ResponseSoftware Supply Chain

The Unapproved Skill in the Build Log
Learn how to trace an unapproved agent skill through CI logs, prove what ran, and close the approval gaps that hid it.
Ci SecurityAgent SkillsBuild LogsSoftware Supply Chain

The Commit That Was Not Yours
Found an unfamiliar AI-authored commit? Learn how to trace its origin, contain access and restore safe merges without trusting the diff alone.
Ai AgentsSoftware Supply ChainGithub SecurityAccess Control

What Happens When a Feature Commit Hides a Supply Chain Attack?
A small feature commit can carry a poisoned dependency. Learn what to inspect before hidden code reaches your build or production systems.
Software Supply ChainDependency SecurityMalicious PackagesCode Review