Tech News
Все новости AI & ML Architecture DevOps Open Source Programming Team Management Testing & QA Web

Последние новости

⚑ Сообщить о проблеме

Tech news from the best sources

Все темы - игры AI Gear News Tech agents ai api architecture automation beginners career database devops javascript llm machinelearning mcp opensource performance productivity programming python react security showdev testing tutorial typescript webdev
Все EN RU
EN

Flux Mirror Uses Gitless GitOps to Keep Software Supply Chain Under Control

Flux has introduced Flux Mirror, a CLI plugin that mirrors container images, Helm charts and OCI artifacts between registries from a declarative con…

KubernetesSoftware Supply ChainGitOpsDevOpsnews
InfoQ Aug 20, 2026, 08:00 UTC
EN

GitHub Hardens npm and Actions Defaults, Drawing Debate over Delays versus Signing

GitHub consolidated the npm and Actions changes it shipped from March to July 2026 against supply chain attacks, several of which alter defaults rat…

Software Supply ChainAutomationGitHub ActionsOpen SourcegithubContinuous DeliverySecurityDevelopmentDevOpsnews
InfoQ Aug 8, 2026, 07:45 UTC
EN

GitHub Introduces Default "Cooldown" Policy for Dependabot Version Updates

Instead of immediately opening pull requests when newer dependency versions are released, Dependabot now waits three days before suggesting upgrades…

githubSecurity VulnerabilitiesSoftware Supply ChainDependency ManagementDevOpsDevelopmentnews
InfoQ Jul 28, 2026, 19:00 UTC
EN

VS Code 1.123 Adds Two-Hour Extension Update Delay to Limit Supply Chain Attacks

VS Code 1.123 adds a two-hour delay before auto-updating extensions to newly published versions, creating a revocation window against supply chain a…

Visual Studio CodeApplication SecuritySoftware Supply ChainDevelopmentArchitecture & DesignDevOpsnews
InfoQ Jun 18, 2026, 10:15 UTC
EN

Pip 26.1 Ships Dependency Cooldowns and Experimental Lockfile Support to Combat Supply Chain Attacks

Pip 26.1 ships dependency cooldowns that enforce a waiting period before newly published packages can be installed, and experimental pylock.toml loc…

Dependency ManagementPackage ManagersSoftware Supply ChainDevelopmentnews
InfoQ May 20, 2026, 10:04 UTC
EN

TanStack Details Sophisticated npm Supply Chain Attack That Compromised 42 Packages

TanStack has released a detailed postmortem describing a sophisticated supply-chain attack that compromised 42 npm packages and published 84 malicio…

Application SecurityNPMSoftware Supply ChainDevOpsnews
InfoQ May 19, 2026, 12:00 UTC
EN

Leading Open Source Author Calls for Verification over Trust in Software Supply Chains

In a blog post published in March 2026, Daniel Stenberg, creator and lead developer of curl, makes the case that the software industry's default pos…

Dependency ManagementVerificationSoftware Supply ChainCulture & MethodsDevOpsnews
InfoQ May 7, 2026, 07:00 UTC
EN

Attacker Bought 30 WordPress Plugins on Flippa and Backdoored All of Them

An attacker purchased 30+ WordPress plugins on Flippa for six figures, planted a PHP deserialization backdoor in the first commit, and waited eight…

Security VulnerabilitiesApplication SecuritySoftware Supply ChainDependency ManagementDevelopmentArchitecture & Designnews
InfoQ May 6, 2026, 10:00 UTC

© Tech News — Агрегатор новостей

English Русский
Карта сайта Правовая информация Конфиденциальность Условия использования Авторские права / Удаление Контакт DSA

Выход с сайта

Вы собираетесь открыть внешний сайт:

Продолжить →