Finding the vulnerabilities is the easy part
Every named CVE now ships with a single-page site at .vuln.
How we refreshed self-hosted Recoil email with our own RIPE-allocated IPv4 block, and deployed Postfix/rspamd/Dovecot to get full SPF/DKIM/DMARC deliverability.
A survey of install-script allowlist mechanisms across package managers and language ecosystems.
Branch protection is a row in someone else's database
How long until we see a CVE filed against a markdown file?
uBlock Origin for composer install
Stealing user logins by hijacking a vulnerable webview implementation in a mobile app
today iain learned: How to report a miscategorisation of a site/domain in the Cloudflare for Families DNS resolver service.
Thank you Dr. Zizmor
TUF, in-toto, and Sigstore only look pointless while nothing is on fire
An experimental implementation of the DTLS protocol is coming to Node.js, bringing TLS-equivalent security to datagram-based communication over UDP.
apt install -t unstable, but make it your whole personality
How curl's disclosure policy filtered an AI scanner's findings at source
The streetlight effect in project-health scoring
Which of your dependencies are wearing sunglasses
The riskiest projects in open source, scored a decade early
The non-CVE half of package manager security
Recurring weakness classes in package managers
What to do when upstream ghosts you
Anne Robinson would like a word with .github/workflows
This keeps happening.
Denial, anger, bargaining, depression, acceptance, postinstall.
A knowledge base of project conventions, exposed as a CLI.
Lockfiles, sandboxes, and cooldown timers.
Packages all the way down, agents all the way up.
Anthropic's Mythos makes autonomous vulnerability chaining across devices a sudden reality, so I've been thinking about how digital 'antibotty' inoculation networks may be needed far sooner than I expected.
Stretching a metaphor deep into the floor.
The npm client's default settings are a root cause of JavaScript's recurring supply chain security problems.
A short writeup of finding a stored XSS vulnerability in an AI powered writing app
It's exactly what you'd expect.
Electron's safeStorage uses DPAPI on Windows, which means any process running as your user can decrypt Signal's database. on macOS, Keychain actually isolates per-app.
Notes on ENISA's Technical Advisory for Secure Use of Package Managers.