SLSA

supply chain levels, software attestation, build provenance, SLSA framework

Feeds to Scour
SubscribedAll
Scoured 46 posts in 15.3 ms

VEX demo update: adding Docker Scout attestations (and three new gotchas)

 🖼️Immich  Content type: Code
github.com··DEV

Securing CI/CD for an open source project: Locking down dependencies

 🤖Automation  Content type: Blog
cncf.io·

Miasma Worm Compromises 73 Microsoft GitHub Repositories

 🌟cool github projects
securityaffairs.com·

‘Jinsei’ Review:  An Eerie Philosophy of Fame is Fine-Lined in a Spellbindingly Strange Anime Debut

 🔏Sigstore  Content type: News
variety.com·

Release v1.88.0 · BerriAI/litellm

 🧠AI  Content type: Code
github.com·

Hear Ella Langley’s Shania Twain–Approved ‘You’re Still the One’ Cover

 🔏Sigstore  Content type: News
rollingstone.com
·

Broadcom’s Tanzu Division Prepares Historic Spring Patch Release Amid AI Security Surge

 🛡️Computer Security
sdtimes.com··r/java

AUKUS and the case for no submarines

 🌍Geopolitics

Release v1.84.6 · BerriAI/litellm

 🔏Sigstore  Content type: Code
github.com·

Timothée and Kylie Are the Best Dressed Courtside Couple — Shop Their Looks Starting at $20

 🔏Sigstore  Content type: News
popsugar.com·

Broadcom beefs up Spring security to protect against AI-enabled attacks

 🛡️Computer Security  Content type: News

Release v2026.6.4: Declarative system packages · jdx/mise

 💻CLI Tools  Content type: Code  Content type: Release
github.com·

Ten years. Ten discoveries about trust.

 🤖AI agents  Content type: Blog
medium.com
·

Spring is 23 years old. AI just made it a security emergency.

 🛡️Computer Security
thenewstack.io·

AlvisoOculus/optionsahoy-mcp: Equity comp tax (ISO/NSO/RSU/QSBS), concentration, and hedging optimizer. MCP server + REST API with federal + 50-state + DC tax code, multi-year horizons.

 🧠AI  Content type: Code
github.com··Hacker News

Release Step CLI v0.30.3-rc1 (26-06-10) · smallstep/cli

 🌟cool github projects  Content type: Code
github.com·

Teyana Taylor Named BET Awards 2026 Icon of the Year

 🔏Sigstore  Content type: News
rollingstone.com
·

inflightsec/agent-vault-proxy: Just-in-time API keys for AI agents - and any other process you route through it: the caller only ever sees a placeholder.

 🤖AI agents  Content type: Code
github.com··Hacker News

Shai-Hulud copycat campaign targets Python developers through PyPI typosquatting

 🤖Automation  Content type: Blog
about.gitlab.com·

someone actually leaked the Miasma supply chain attack toolkit source code on github

 🌟cool github projects

Keyboard Shortcuts

Navigation

Next / previous item
j/k
Open post
oorEnter
Preview post
v

Post Actions

Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Save / unsave
s

Recommendations

Add interest / feed
Enter
Not interested
x

Go to

Home
gh
Interests
gi
Feeds
gf
Likes
gl
History
gy
Changelog
gc
Settings
gs
Browse
gb
Search
/

General

Show this help
?
Submit feedback
!
Close modal / unfocus
Esc

Press ? anytime to show this help