Skip to main content
Scour
Discover
Docs
Login
Sign Up
Discover
About
Docs
Changelog
You are offline. Trying to reconnect...
Copied to clipboard
Unable to share or copy to clipboard
🔗 Software Supply Chain
arxiv.org
·
6d
6 days ago
Software
Dark Matter: Gazing at Uncharted Files to Navigate
SBOM
Integrations
Covered by
Andrew Nesbitt
Love
Like
Not for me
Save
Add to your feed
Feeds
Share
Report
Off Topic
Harmful Content
Low Quality
Spam
Misleading
Duplicate
Wrong Language
Block Domain
Actions for Software Dark Matter: Gazing at Uncharted Files to Navigate SBOM Integrations
hextrap.com
·
4d
4 days ago
Package
Firewall with OPA Policies and MCP Support
Covers
Open Policy Agent - Homepage | Open Policy Agent
Discussed on
Hacker News
Love
Like
Not for me
Save
Add to your feed
Feeds
Share
Report
Off Topic
Harmful Content
Low Quality
Spam
Misleading
Duplicate
Wrong Language
Block Domain
Actions for Package Firewall with OPA Policies and MCP Support
guaracloud.github.io
·
2d
2 days ago
Purple Wolf – A fast, verifiable WAF for Traefik
Discussed on
Hacker News
Love
Like
Not for me
Save
Add to your feed
Feeds
Share
Report
Off Topic
Harmful Content
Low Quality
Spam
Misleading
Duplicate
Wrong Language
Block Domain
Actions for Purple Wolf – A fast, verifiable WAF for Traefik
GitHub
·
5d
5 days ago
Show HN: Marshal – behavioral
supply-chain
scanner for JVM
dependencies
Discussed on
Hacker News
Love
Like
Not for me
Save
Add to your feed
Feeds
Share
Report
Off Topic
Harmful Content
Low Quality
Spam
Misleading
Duplicate
Wrong Language
Block Domain
Actions for Show HN: Marshal – behavioral supply-chain scanner for JVM dependencies
datanexusmcp.com
·
3d
3 days ago
September 2025 NPM
Attack
Hit 2.6B Weekly Downloads. Most Found Out on Twitter
Covers
2 stories
See all stories this covers
including
The npm Threat Landscape: Attack Surface and Mitigations
Discussed on
Hacker News
Love
Like
Not for me
Save
Add to your feed
Feeds
Share
Report
Off Topic
Harmful Content
Low Quality
Spam
Misleading
Duplicate
Wrong Language
Block Domain
Actions for September 2025 NPM Attack Hit 2.6B Weekly Downloads. Most Found Out on Twitter
i-programmer.info
·
3d
3 days ago
Perplexity Releases The Bumblebee
Supply
Chain
Security
Scanner
Covers
perplexityai/bumblebee: Read-only inventory collector for package, extension, and developer-tool metadata on macOS and Linux developer endpoints, built for fast supply-chain exposure checks.
Love
Like
Not for me
Save
Add to your feed
Feeds
Share
Report
Off Topic
Harmful Content
Low Quality
Spam
Misleading
Duplicate
Wrong Language
Block Domain
Actions for Perplexity Releases The Bumblebee Supply Chain Security Scanner
worklifenotes.com
·
3d
3 days ago
CI/CD
Security
Principles in 2026
Covers
Static Analysis for GitHub Actions
Discussed on
Hacker News
Love
Like
Not for me
Save
Add to your feed
Feeds
Share
Report
Off Topic
Harmful Content
Low Quality
Spam
Misleading
Duplicate
Wrong Language
Block Domain
Actions for CI/CD Security Principles in 2026
endorlabs.com
·
4d
4 days ago
Mastra compromised in
supply
chain
attack
Covered by
news.risky.biz
Discussed on
Hacker News
Love
Like
Not for me
Save
Add to your feed
Feeds
Share
Report
Off Topic
Harmful Content
Low Quality
Spam
Misleading
Duplicate
Wrong Language
Block Domain
Actions for Mastra compromised in supply chain attack
manveerc.substack.com
·
5d
5 days ago
Smarter Models, Dumber
Security
Covers
2 stories
See all stories this covers
including
Model Context Protocol And OAuth
Discussed on
Substack
Love
Like
Not for me
Save
Add to your feed
Feeds
Share
Report
Off Topic
Harmful Content
Low Quality
Spam
Misleading
Duplicate
Wrong Language
Block Domain
Actions for Smarter Models, Dumber Security
stepsecurity.io
·
4d
4 days ago
Mastra NPM
Supply
Chain
Attack
: 140 Packages Backdoor via easy-day-JS Typosquat
Covered by
5 sources
See all sources covering this story
including
thehackernews.com
,
Malware Analysis, News and Indicators
Discussed on
Hacker News
Love
Like
Not for me
Save
Add to your feed
Feeds
Share
Report
Off Topic
Harmful Content
Low Quality
Spam
Misleading
Duplicate
Wrong Language
Block Domain
Actions for Mastra NPM Supply Chain Attack: 140 Packages Backdoor via easy-day-JS Typosquat
hackernoon.com
·
5d
5 days ago
GitGuardian Announces Endpoint Protection
Love
Like
Not for me
Save
Add to your feed
Feeds
Share
Report
Off Topic
Harmful Content
Low Quality
Spam
Misleading
Duplicate
Wrong Language
Block Domain
Actions for GitGuardian Announces Endpoint Protection
Determinate Systems
·
1w
1 week ago
Nixpkgs Cooldowns
Covers
3 stories
See all stories this covers
including
PSA: AUR is down only on ipv4. Enable ipv6 to get it working again.
Covered by
Linuxiac
Discussed on
Hacker News
Love
Like
Not for me
Save
Add to your feed
Feeds
Share
Report
Off Topic
Harmful Content
Low Quality
Spam
Misleading
Duplicate
Wrong Language
Block Domain
Actions for Nixpkgs Cooldowns
johnstawinski.com
·
3d
3 days ago
Repo-Jacking Anthropic's Claude Community Plugins (and the SHAs That Saved Them)
Discussed on
Hacker News
Love
Like
Not for me
Save
Add to your feed
Feeds
Share
Report
Off Topic
Harmful Content
Low Quality
Spam
Misleading
Duplicate
Wrong Language
Block Domain
Actions for Repo-Jacking Anthropic's Claude Community Plugins (and the SHAs That Saved Them)
theregister
·
5d
5 days ago
Python dev saved from disaster by intuition and AI
Covers
3 stories
See all stories this covers
including
Upcoming breaking changes for npm v12 - GitHub Changelog
Discussed on
Hacker News
Love
Like
Not for me
Save
Add to your feed
Feeds
Share
Report
Off Topic
Harmful Content
Low Quality
Spam
Misleading
Duplicate
Wrong Language
Block Domain
Actions for Python dev saved from disaster by intuition and AI
Socket
·
4d
4 days ago
Socket Firewall
Covered by
Huli's blog
Discussed on
Hacker News
Love
Like
Not for me
Save
Add to your feed
Feeds
Share
Report
Off Topic
Harmful Content
Low Quality
Spam
Misleading
Duplicate
Wrong Language
Block Domain
Actions for Socket Firewall
GitHub
·
1d
1 day ago
Muninn: 8
Security
scanners in one GitHub Action
Covered by
indiehacker.news
Discussed on
Hacker News
Love
Like
Not for me
Save
Add to your feed
Feeds
Share
Report
Off Topic
Harmful Content
Low Quality
Spam
Misleading
Duplicate
Wrong Language
Block Domain
Actions for Muninn: 8 Security scanners in one GitHub Action
Huntress Blog
·
3d
3 days ago
Cybercrime Breaches Klue: Salesforce Data Impacted for Many Victims, including Huntress
Covered by
5 sources
See all sources covering this story
including
BleepingComputer
,
SecurityWeek
Love
Like
Not for me
Save
Add to your feed
Feeds
Share
Report
Off Topic
Harmful Content
Low Quality
Spam
Misleading
Duplicate
Wrong Language
Block Domain
Actions for Cybercrime Breaches Klue: Salesforce Data Impacted for Many Victims, including Huntress
tirith.sh
·
2d
2 days ago
Detect terminal injection, homograph, and pipe-to-shell
attacks
Discussed on
Hacker News
Love
Like
Not for me
Save
Add to your feed
Feeds
Share
Report
Off Topic
Harmful Content
Low Quality
Spam
Misleading
Duplicate
Wrong Language
Block Domain
Actions for Detect terminal injection, homograph, and pipe-to-shell attacks
TNW | Data-Security
·
5d
5 days ago
Attackers
hijacked over 1,500 Arch Linux
packages
to steal developers’ secrets, no hacking required
Covers
Active AUR malicious packages incident
Discussed on
Hacker News
Love
Like
Not for me
Save
Add to your feed
Feeds
Share
Report
Off Topic
Harmful Content
Low Quality
Spam
Misleading
Duplicate
Wrong Language
Block Domain
Actions for Attackers hijacked over 1,500 Arch Linux packages to steal developers’ secrets, no hacking required
hackernoon.com
·
3d
3 days ago
What Are Some Best Practices for Pipeline
Security
?
Love
Like
Not for me
Save
Add to your feed
Feeds
Share
Report
Off Topic
Harmful Content
Low Quality
Spam
Misleading
Duplicate
Wrong Language
Block Domain
Actions for What Are Some Best Practices for Pipeline Security?
Page 2 »
Log in to enable infinite scrolling
Keyboard Shortcuts
Navigation
Next / previous post
j
/
k
Open post
o
or
Enter
Preview post
v
Post Actions
Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Save / unsave
s
Recommendations
Add interest / feed
Enter
Not interested
x
Go to
Home
g
h
Interests
g
i
Feeds
g
f
Likes
g
l
History
g
y
Changelog
g
c
Settings
g
s
Discover
g
b
Search
/
Pagination
Next page
n
Previous page
p
General
Show this help
?
Submit feedback
!
Close modal / unfocus
Esc
Press
?
anytime to show this help
Like
Save
Not for me
Report