GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption
Ravie LakshmananJul 27, 2026Software Supply Chain / DevSecOps GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool...
Ravie LakshmananJul 27, 2026Software Supply Chain / DevSecOps GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool...
Ravie LakshmananJul 21, 2026Software Security / Artificial Intelligence Google's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber,...
Ravie LakshmananJul 17, 2026Software Supply Chain / Malware Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting...
Ravie LakshmananJul 10, 2026Software Supply Chain / Malware Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and...
Ravie LakshmananJun 08, 2026Software Supply Chain / Malware Microsoft has announced that Visual Studio Code (VS Code) will apply a...
Ravie LakshmananMay 23, 2026Software Supply Chain / DevSecOps GitHub has rolled out new controls for npm to improve the security...
Ravie LakshmananMay 19, 2026Software Security / Malware In yet another software supply chain attack, threat actors have compromised the popular...
Ravie LakshmananMar 27, 2026Software Security / DevSecOps Cybersecurity researchers have disclosed details of a now-patched bug impacting Open VSX's pre-publish...
Ravie LakshmananFeb 04, 2026Software Security / Vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a critical...