Tag
5 articles tagged Software Supply Chain.
-
Cal.com co-founder Pierre Richelson details the pivot to private commercial forks due to AI-driven security risks. The episode analyzes how AI flattens the knowledge graph, increases vulnerability exposure, and forces commercial open source businesses to rethink their public codebase strategies.
-
Tanya Janka, project leader for the OWASP Top 10 2025, discusses the inclusion of vibe coding as a critical risk. The analysis covers the shift from vulnerability memorization to secure coding habits, the expansion of supply chain threats to include human developers, and actionable strategies for engineering leaders to integrate security into AI-assisted workflows.
-
Dan Lorink of Chainguard analyzes the exponential divergence between AI-driven development speed and legacy security postures. This brief outlines strategies for securing autonomous agents, optimizing CI/CD pipelines for high-volume code generation, and adapting open source maintenance models to agentic workflows.
-
Andres Almiray discusses the strategic roadmap for JReleaser 2.0, focusing on cross-language adoption, breaking changes, and the Common House Foundation's governance model. The analysis covers how established open source projects can leverage low-governance structures to ensure sustainability and security compliance under the Cyber Resilience Act.
-
Nicholas C. Zakas analyzes the critical security vulnerabilities in the NPM registry, arguing that GitHub's current response shifts burden to maintainers without solving systemic risks. The discussion highlights the failure of alternatives like JSR and proposes actionable security frameworks for package distribution.