Ci cd
1 AI tool 5 articles
Advertisement
AI tools1
Articles5
npm v12 Is Here, and It Turns Off a Default That Has Run Arbitrary Code for a Decade
npm v12 went generally available on 8 July, flipping install scripts, Git dependencies and remote-URL packages...
KE
11 Jul
npm v12 Flips Three Install Defaults From Automatic to Opt-In — Prepare Your Pipelines Now
GitHub's npm v12, due July 2026, turns three things npm install does automatically today into choices you have...
KE
19 Jun
Miasma: How a Hijacked CI Pipeline Shipped Malicious npm Packages With Valid Provenance
The Miasma supply-chain attack didn't typosquat or steal an npm token — it hijacked a maintainer's CI pipeline...
KE
8 Jun
Megalodon Campaign Backdoors 5,561 GitHub Repos in Six Hours — Inside the Largest GitHub Actions Supply-Chain Attack on Record
An automated campaign called Megalodon pushed 5,718 malicious commits to 5,561 GitHub repos between 18-21 May...
CY
21 May
Critical GitHub RCE Flaw CVE-2026-3854 Lets Attackers Execute Code With a Single Git Push — Patch Now
CVE-2026-3854, a CVSS 9.8 RCE flaw in GitHub Enterprise Server, allows unauthenticated code execution via a si...
CY
8 May
Advertisement