<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>supply chain</title>
    <link rel="self" type="application/atom+xml" href="https://links.pgmac.net.au/guest/tags/367/feed"/>
    <updated>2026-05-06T23:10:07+10:00</updated>
    <id>https://links.pgmac.net.au/guest/tags/367/feed</id>
            <entry>
            <id>https://links.pgmac.net.au/links/1688</id>
            <title type="text"><![CDATA[axios@1.14.1 and axios@0.30.4 are compromised · Issue #10604 · axios/axios · GitHub]]></title>
            <link rel="alternate" href="https://github.com/axios/axios/issues/10604#issuecomment-4160410930" />
            <link rel="via" type="application/atom+xml" href="https://links.pgmac.net.au/links/1688"/>
            <author>
                <name><![CDATA[Paul Macdonnell]]></name>
            </author>
            <summary type="text">
                <![CDATA[more details: https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan Most likely, a maintainer&amp;#039;s GitHub and npm accounts are compromised as these issues are getting deleted. I have also rep...]]>
            </summary>
            <updated>2026-03-31T22:58:13+10:00</updated>
        </entry>
            <entry>
            <id>https://links.pgmac.net.au/links/1671</id>
            <title type="text"><![CDATA[Judge blocks Pentagon effort to &amp;#039;punish&amp;#039; Anthropic with supply chain risk label]]></title>
            <link rel="alternate" href="https://www.cnn.com/2026/03/26/business/anthropic-pentagon-injunction-supply-chain-risk" />
            <link rel="via" type="application/atom+xml" href="https://links.pgmac.net.au/links/1671"/>
            <author>
                <name><![CDATA[Paul Macdonnell]]></name>
            </author>
            <summary type="text">
                <![CDATA[A federal judge in California has indefinitely blocked the Pentagon’s effort to “punish” Anthropic by labeling it a supply chain risk and attempting to sever government ties with the AI company, ruling that those measures ran roughshod over its constitutional rights.]]>
            </summary>
            <updated>2026-03-27T14:27:12+10:00</updated>
        </entry>
            <entry>
            <id>https://links.pgmac.net.au/links/1647</id>
            <title type="text"><![CDATA[TeamPCP deploys CanisterWorm on NPM following Trivy compromise]]></title>
            <link rel="alternate" href="https://www.aikido.dev/blog/teampcp-deploys-worm-npm-trivy-compromise" />
            <link rel="via" type="application/atom+xml" href="https://links.pgmac.net.au/links/1647"/>
            <author>
                <name><![CDATA[Paul Macdonnell]]></name>
            </author>
            <summary type="text">
                <![CDATA[]]>
            </summary>
            <updated>2026-03-21T10:34:27+10:00</updated>
        </entry>
            <entry>
            <id>https://links.pgmac.net.au/links/1567</id>
            <title type="text"><![CDATA[Statement on the comments from Secretary of War Pete Hegseth]]></title>
            <link rel="alternate" href="https://www.anthropic.com/news/statement-comments-secretary-war" />
            <link rel="via" type="application/atom+xml" href="https://links.pgmac.net.au/links/1567"/>
            <author>
                <name><![CDATA[Paul Macdonnell]]></name>
            </author>
            <summary type="text">
                <![CDATA[Anthropic&amp;#039;s response to the Secretary of War and advice for customers]]>
            </summary>
            <updated>2026-03-01T00:14:33+10:00</updated>
        </entry>
            <entry>
            <id>https://links.pgmac.net.au/links/1503</id>
            <title type="text"><![CDATA[Sandwich Bill of Materials]]></title>
            <link rel="alternate" href="https://nesbitt.io/2026/02/08/sandwich-bill-of-materials.html" />
            <link rel="via" type="application/atom+xml" href="https://links.pgmac.net.au/links/1503"/>
            <author>
                <name><![CDATA[Paul Macdonnell]]></name>
            </author>
            <summary type="text">
                <![CDATA[SBOM 1.0: A specification for sandwich supply chain transparency.]]>
            </summary>
            <updated>2026-02-14T14:02:21+10:00</updated>
        </entry>
            <entry>
            <id>https://links.pgmac.net.au/links/1394</id>
            <title type="text"><![CDATA[Supply Chain Vuln Compromised Core AWS GitHub Repos &amp;amp; Threatened the AWS Console]]></title>
            <link rel="alternate" href="https://www.wiz.io/blog/wiz-research-codebreach-vulnerability-aws-codebuild" />
            <link rel="via" type="application/atom+xml" href="https://links.pgmac.net.au/links/1394"/>
            <author>
                <name><![CDATA[Paul Macdonnell]]></name>
            </author>
            <summary type="text">
                <![CDATA[]]>
            </summary>
            <updated>2026-01-16T06:16:22+10:00</updated>
        </entry>
            <entry>
            <id>https://links.pgmac.net.au/links/1099</id>
            <title type="text"><![CDATA[We all dodged a bullet - Xe Iaso]]></title>
            <link rel="alternate" href="https://xeiaso.net/notes/2025/we-dodged-a-bullet/" />
            <link rel="via" type="application/atom+xml" href="https://links.pgmac.net.au/links/1099"/>
            <author>
                <name><![CDATA[Paul Macdonnell]]></name>
            </author>
            <summary type="text">
                <![CDATA[That NPM attack could have been so much worse.]]>
            </summary>
            <updated>2025-09-10T10:56:18+10:00</updated>
        </entry>
            <entry>
            <id>https://links.pgmac.net.au/links/1066</id>
            <title type="text"><![CDATA[The Critical Flaw in CVE Scoring]]></title>
            <link rel="alternate" href="https://www.darkreading.com/vulnerabilities-threats/critical-flaw-cve-scoring" />
            <link rel="via" type="application/atom+xml" href="https://links.pgmac.net.au/links/1066"/>
            <author>
                <name><![CDATA[Paul Macdonnell]]></name>
            </author>
            <summary type="text">
                <![CDATA[With informed decision-making, organizations can strengthen their overall resilience and maintain the agility needed to adapt to emerging threats, without sacrificing innovation or productivity.]]>
            </summary>
            <updated>2025-10-05T12:50:35+10:00</updated>
        </entry>
            <entry>
            <id>https://links.pgmac.net.au/links/907</id>
            <title type="text"><![CDATA[Using artifact attestations to establish provenance for builds - GitHub Docs]]></title>
            <link rel="alternate" href="https://docs.github.com/en/actions/security-for-github-actions/using-artifact-attestations/using-artifact-attestations-to-establish-provenance-for-builds#verifying-artifact-attestations-with-the-github-cli" />
            <link rel="via" type="application/atom+xml" href="https://links.pgmac.net.au/links/907"/>
            <author>
                <name><![CDATA[Paul Macdonnell]]></name>
            </author>
            <summary type="text">
                <![CDATA[]]>
            </summary>
            <updated>2025-05-31T15:31:32+10:00</updated>
        </entry>
            <entry>
            <id>https://links.pgmac.net.au/links/851</id>
            <title type="text"><![CDATA[AI-hallucinated code dependencies become new supply chain risk]]></title>
            <link rel="alternate" href="https://www.bleepingcomputer.com/news/security/ai-hallucinated-code-dependencies-become-new-supply-chain-risk/" />
            <link rel="via" type="application/atom+xml" href="https://links.pgmac.net.au/links/851"/>
            <author>
                <name><![CDATA[Paul Macdonnell]]></name>
            </author>
            <summary type="text">
                <![CDATA[A new class of supply chain attacks named &amp;#039;slopsquatting&amp;#039; has emerged from the increased use of generative AI tools for coding and the model&amp;#039;s tendency to &amp;quot;hallucinate&amp;quot; non-existent package names.]]>
            </summary>
            <updated>2025-05-28T01:04:05+10:00</updated>
        </entry>
            <entry>
            <id>https://links.pgmac.net.au/links/826</id>
            <title type="text"><![CDATA[reviewdog/action-setup]]></title>
            <link rel="alternate" href="https://www.wiz.io/blog/new-github-action-supply-chain-attack-reviewdog-action-setup" />
            <link rel="via" type="application/atom+xml" href="https://links.pgmac.net.au/links/826"/>
            <author>
                <name><![CDATA[Paul Macdonnell]]></name>
            </author>
            <summary type="text">
                <![CDATA[]]>
            </summary>
            <updated>2025-05-28T01:00:07+10:00</updated>
        </entry>
            <entry>
            <id>https://links.pgmac.net.au/links/824</id>
            <title type="text"><![CDATA[GitHub Actions now supports a digest for validating your artifacts at runtime - GitHub Changelog]]></title>
            <link rel="alternate" href="https://github.blog/changelog/2025-03-18-github-actions-now-supports-a-digest-for-validating-your-artifacts-at-runtime/" />
            <link rel="via" type="application/atom+xml" href="https://links.pgmac.net.au/links/824"/>
            <author>
                <name><![CDATA[Paul Macdonnell]]></name>
            </author>
            <summary type="text">
                <![CDATA[Developers using upload-artifact and download-artifact in their Actions workflows can now ensure the integrity of their artifacts with the new SHA256 digest. This feature automatically verifies that the artifact uploaded…]]>
            </summary>
            <updated>2025-05-28T00:59:09+10:00</updated>
        </entry>
            <entry>
            <id>https://links.pgmac.net.au/links/799</id>
            <title type="text"><![CDATA[Recent improvements to Artifact Attestations - GitHub Changelog]]></title>
            <link rel="alternate" href="https://github.blog/changelog/2025-02-18-recent-improvements-to-artifact-attestations/" />
            <link rel="via" type="application/atom+xml" href="https://links.pgmac.net.au/links/799"/>
            <author>
                <name><![CDATA[Paul Macdonnell]]></name>
            </author>
            <summary type="text">
                <![CDATA[We released a collection of improvements to Artifact Attestations to make the verification of attestations easier and more consistent. Artifact Attestations let you create provenance signatures, which provide an unforgeable…]]>
            </summary>
            <updated>2025-05-28T00:55:08+10:00</updated>
        </entry>
            <entry>
            <id>https://links.pgmac.net.au/links/730</id>
            <title type="text"><![CDATA[Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection - Flatt Secu]]></title>
            <link rel="alternate" href="https://flatt.tech/research/posts/compromising-openwrt-supply-chain-sha256-collision/" />
            <link rel="via" type="application/atom+xml" href="https://links.pgmac.net.au/links/730"/>
            <author>
                <name><![CDATA[Paul Macdonnell]]></name>
            </author>
            <summary type="text">
                <![CDATA[Introduction
Hello, I’m RyotaK (@ryotkak
), a security engineer at Flatt Security Inc.
A few days ago, I was upgrading my home lab network, and I decided to upgrade the OpenWrt
 on my router.1 After accessing the LuCI, which is the web interface of OpenWrt, I noticed that there is a section called Attended Sysupgrade, so I tried to upgrade the firmware using it.
After reading the description, I found that it states it builds new firmware using an online service.]]>
            </summary>
            <updated>2026-01-26T04:00:32+10:00</updated>
        </entry>
            <entry>
            <id>https://links.pgmac.net.au/links/694</id>
            <title type="text"><![CDATA[Are we PEP 740 yet? 🔏]]></title>
            <link rel="alternate" href="https://trailofbits.github.io/are-we-pep740-yet/" />
            <link rel="via" type="application/atom+xml" href="https://links.pgmac.net.au/links/694"/>
            <author>
                <name><![CDATA[Paul Macdonnell]]></name>
            </author>
            <summary type="text">
                <![CDATA[]]>
            </summary>
            <updated>2026-01-24T04:00:26+10:00</updated>
        </entry>
            <entry>
            <id>https://links.pgmac.net.au/links/578</id>
            <title type="text"><![CDATA[https://www.reuters.com/world/middle-east/dozens-hezbollah-members-wounded-lebanon-when-pagers-exploded-sources-witnesses-2024-09-17/]]></title>
            <link rel="alternate" href="https://www.reuters.com/world/middle-east/dozens-hezbollah-members-wounded-lebanon-when-pagers-exploded-sources-witnesses-2024-09-17/" />
            <link rel="via" type="application/atom+xml" href="https://links.pgmac.net.au/links/578"/>
            <author>
                <name><![CDATA[Paul Macdonnell]]></name>
            </author>
            <summary type="text">
                <![CDATA[]]>
            </summary>
            <updated>2025-12-24T06:00:29+10:00</updated>
        </entry>
            <entry>
            <id>https://links.pgmac.net.au/links/480</id>
            <title type="text"><![CDATA[Artifact Attestations is generally available]]></title>
            <link rel="alternate" href="https://github.blog/changelog/2024-06-25-artifact-attestations-is-generally-available/" />
            <link rel="via" type="application/atom+xml" href="https://links.pgmac.net.au/links/480"/>
            <author>
                <name><![CDATA[Paul Macdonnell]]></name>
            </author>
            <summary type="text">
                <![CDATA[GitHub Artifact Attestations is generally available We’re thrilled to announce the general availability of GitHub Artifact Attestations! Artifact Attestations allow you to guarantee the integrity of artifacts built inside GitHub…]]>
            </summary>
            <updated>2025-12-13T00:00:08+10:00</updated>
        </entry>
    </feed>
