CI/CD Security
Supply Chain Attacks Keep Hitting npm. Here Is What AWS Says Actually Helps
AWS wrote a long post on supply chain security after Shai-Hulud and the other npm attacks this year. We read it so you don't have to. Here is what's actually worth doing.
npm v12 Will Stop Running Install Scripts by Default: What It Means and How to Prepare
npm v12 comes in July 2026 and it changes how npm install works. Install scripts, git dependencies and remote tarballs will be blocked by default. Here is what changes, why, and what you should do now.
Harden Your GitHub: 14 Free Things to Do Right Now
GitHub default settings are made for convenience, not for security. Here are 14 changes you can do today for free. They cover access, Actions, secrets, supply chain and dependencies.
323 npm Packages Poisoned in 22 Minutes: Inside the AntV Supply Chain Attack
On May 19, 2026, a compromised npm account pushed malicious versions of 323 packages across Alibaba's AntV ecosystem. The payload reads GitHub Actions runner memory to extract masked secrets in plaintext. Here is what happened, how it works, and what to do.
10 Rules of GitHub Branch Protection: Why Every Org Should Use Them
Any organisation — from a two-person startup to a global charity — benefits from branch protection rules in GitHub. They’re included for free on public …