Tag: #supply-chain
Writing on GPUs, LLMs, MLOps, Kubernetes — and mindset · 28 posts
Open Source Worth Watching Right Now (6) What Star Counts Do Not Tell You
A star count is a popularity metric, not a risk metric. This post lays out the signals you actually have to check before you bring an open source project into production: recent commits and release cadence, issue respons
2026-08-12 · 6 min read #open-source#governance#supply-chain#risk#devopsOpen Source Worth Watching Right Now (4) Observability and Security
With observability data, volume is cost, and a security tool that never makes it into the pipeline never gets used. This post introduces 12 open source projects that have genuinely taken hold — instrumentation standards,
2026-08-12 · 5 min read #open-source#observability#security#opentelemetry#ebpfBus Factor Is Not the Number of People Who Know the Code but the Number of People Who Can Decide
The Nixpkgs core team disbanded after ten months. In a repository with thousands of contributors, the people holding delegated decision-making authority numbered two, and when those two stepped down that jurisdiction was
2026-08-09 · 9 min read #devops#open-source#governance#nix#supply-chainWhen Open Source Governance Breaks Down — The Ruby Central Dispute and Three Axes of Control
On July 30, 2026, André Arko published "Ruby Central's Destructive Legacy," bringing the RubyGems repository access dispute that began in September 2025 back to the surface after ten months. This post lays out the primar
2026-07-31 · 15 min read #open-source#governance#rubygems#supply-chain#licensingDesigning an Air-Gapped Image Import Pipeline — skopeo, Harbor, and a Reimport Runbook That Doesn't Rot
This post designs the pipeline for a problem almost nobody in air-gapped Kubernetes actually gets right: repeatedly and safely bringing container images in. It covers managing the import list as code, the skopeo sync com
2026-07-31 · 17 min read #kubernetes#air-gap#harbor#skopeo#supply-chainDependency Supply Chain Security — The Things a Lockfile Does Not Block
You wrote a dozen or so packages into package.json, yet more than a thousand get installed. This post explains why transitive dependencies are riskier than direct ones, and uses a real lockfile entry to show why an integ
2026-07-26 · 14 min read #security#supply-chain#npm#sbom#ciDeno 2.9 — The deno desktop Experiment, Lockfile-Preserving Migration, and a 24-Hour Supply-Chain Default
Deno 2.9, released on June 25, 2026, comes down to three stories: deno desktop, an experimental feature for building native desktop apps with the web stack (OS webview by default, an optional bundled CEF); a migration pa
2026-07-17 · 14 min read #javascript#deno#javascript-runtime#node-compatibility#supply-chainOne Issue, the Whole Supply Chain — How an Agent Inside CI Broke, and What the Defenses Actually Bought
The Claude Code GitHub Actions vulnerability that GMO Flatt Security researcher RyotaK disclosed on June 1, 2026 traces, end to end, how an agent dropped into a CI pipeline can become the channel that hands over an entir
2026-07-16 · 21 min read #security#ai#prompt-injection#supply-chain#ci-cdDebian Has Started Blocking Unreproducible Packages From Migrating to Testing — What the Gate Actually Blocks, and What It Doesn't
On May 9, 2026, Debian's release team wired its migration software, britney, to reproducibility checks. The sentence that hit the mailing list the next day was "Debian must ship reproducible packages," but what's actuall
2026-07-16 · 20 min read #devops#reproducible-builds#debian#supply-chain#ci-cdThe 3-Hour axios Account Takeover — Provenance Was On, and Nobody Checked It
At 00:21 UTC on March 31, 2026, a malicious version 1.14.1 landed on axios, a package with over 80 million weekly downloads. What makes this case interesting is that axios was already using npm trusted publishing — the l
2026-07-16 · 18 min read #security#supply-chain#npm#nodejs#devsecopsWhy npm supply-chain attacks won't go away — what npm-scan actually checks, and the defenses that work
npm supply-chain attacks are not isolated accidents but a recurring product of install scripts, transitive dependencies, and typosquatting. In 2025 the Shai-Hulud worm self-replicated through install scripts and harveste
2026-07-11 · 7 min read #npm#supply-chain#security#javascript#nodejsGlobal Supply Chains and Daily Life — Where Do My Things Come From
From the cup of coffee you drink in the morning to the smartphone in your hand, daily life rests on a vast invisible supply chain. This essay explores how supply chains work, the history of the container revolution, pand
2026-06-21 · 33 min read #economics#globalization#supply-chain#logistics#historyGlobal Supply Chains and Daily Life — Where Do My Things Come From?
The morning cup of coffee in your hand and the smartphone on your nightstand each tie together dozens of countries. This essay traces how the vast, invisible web we call the global supply chain works, how it delivered ch
2026-06-21 · 36 min read #supply-chain#globalization#logistics#economy#tradeThe AI Semiconductor Supply Chain and Market — Who Actually Makes the Chips (2026)
We trace the value chain behind a single AI chip — design, EDA, IP, foundry, packaging, HBM, and equipment. From TSMC and Samsung to ASML EUV, the CoWoS bottleneck, geopolitics and export controls, the rise of in-house c
2026-06-16 · 19 min read #gpu-cuda#ai-hardware#semiconductor#supply-chain#tsmcOperator Security — Least-Privilege RBAC, Multi-Tenancy, Supply Chain
An Operator runs cluster-wide with powerful privileges, so a single compromise can endanger the whole cluster. This article covers Operator security end to end — generating least-privilege RBAC with markers, choosing Rol
2026-06-15 · 21 min read #kubernetes#operator#rbac#security#supply-chainAnatomy of npm Supply Chain Attacks — Defense Strategies for the Era When Even Red Hat Got Hit
Triggered by the June 2026 incident in which even official Red Hat Cloud Services npm packages were exposed to malicious code, this post dissects the types of npm supply chain attacks and lays out the defense stack organ
2026-06-12 · 17 min read #npm#supply-chain#security#devops#sigstoreCloud Security 2026 Complete Guide - Zero Trust, SBOM/SLSA, CSPM/CNAPP, Wiz, Falco, Sigstore, Vault, Tailscale, Cloudflare Deep Dive
A complete look at the cloud security stack as of May 2026. Zero Trust (Cloudflare, Tailscale, Zscaler, Netskope), CSPM/CNAPP (Wiz, Orca, Lacework, Prisma Cloud, Sysdig, Aqua), SBOM/SLSA supply chain (Sigstore cosign, Cy
2026-05-16 · 22 min read #cloud-security#zero-trust#sbom#slsa#cspmAI Shipping, Logistics, and Supply Chain 2026 Complete Guide - Deep Dive on Project44, FourKites, Convoy, Flexport, ShipBob, Loadsmart, Blue Yonder, and o9 Solutions
The 2026 reshuffling of global supply chains - from Project44 and FourKites real-time visibility, Flexport digital forwarding, the death and rebirth of Convoy, ShipBob D2C fulfillment, to Blue Yonder and o9 Solutions S&O
2026-05-16 · 19 min read #ai-shipping#logistics#supply-chain#project44#fourkitesFrontend Security 2025 — XSS, CSRF, CSP, Trusted Types, JWT, OAuth, PKCE, Passkeys, Supply Chain, SRI (S6 E9)
XSS still tops every CVE report. But 2024–2025 shipped real tools to defeat it: Trusted Types, CSP v3 with strict-dynamic, Sanitizer API. Passkeys replaced passwords for serious products. Supply-chain attacks made SRI +
2026-04-15 · 6 min read #frontend#security#xss#csrf#cspWeb Security Attack and Defense in Practice — XSS, CSRF, SSRF, Clickjacking, Prototype Pollution, Supply Chain, CORS Complete Guide (2025)
If the previous Security post was about "security for the organization", this one is about "the vulnerabilities lodged in your code". The three kinds of XSS with CSP nonce and Trusted Types, CSRF after SameSite, the SSRF
2026-04-15 · 12 min read #web-security#xss#csrf#ssrf#clickjacking