Software Supply Chain
Coverage of Software Supply Chain in the Nexus archive.
- AI-generated code has made security debt a governance problem
AI-generated code accelerates software development but creates security debt due to the speed of risk introduction exceeding human-scale governance processes. Security leaders must address vulnerabilities like insecure patterns, unsafe dependencies, and supply-chain risks introduced by AI tools.
- Rust-Written IronWorm Hits NPM Supply Chain
A Rust-written malware called IronWorm is targeting the NPM supply chain to steal developer credentials and reuse them for propagation. The campaign focuses on compromising software supply channels through credential theft.
- Chainguard Unveils Factory 2.0 to Automate Hardening the Software Supply Chain
Chainguard has launched Factory 2.0, an updated platform designed to enhance software supply chain security through automated hardening. The platform focuses on continuous reconciliation of open source artifacts across containers, libraries, agent skills, and GitHub Actions.