# supply-chain-security

Cybersecurity discipline focused on securing software supply-chain operations and artifacts.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## SymfonyCon Warsaw 2026: The Attack Reached PHP: Composer and Packagist, One Year On

DevFeed: [SymfonyCon Warsaw 2026: The Attack Reached PHP: Composer and Packagist, One Year On](<https://devfeed.tech/articles/symfonycon-warsaw-2026-the-attack-reached-php-composer-and-packagist-one-year-on-31523.md>)

Original publisher: [Read original article](<https://symfony.com/blog/symfonycon-warsaw-2026-the-attack-reached-php-composer-and-packagist-one-year-on>)

Author: Eloïse Charrier

Published: 2026-09-16T12:30:00Z

Content type: article

Language: en

Sources: [Symfony Blog](<https://devfeed.tech/sources/symfony-blog.md>)

Topics: [Symfony](<https://devfeed.tech/topics/symfony.md>), [Composer](<https://devfeed.tech/topics/composer.md>), [PHP](<https://devfeed.tech/topics/php.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [composer](<https://devfeed.tech/tags/composer.md>), [conference](<https://devfeed.tech/tags/conference.md>), [github](<https://devfeed.tech/tags/github.md>), [php](<https://devfeed.tech/tags/php.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [symfony](<https://devfeed.tech/tags/symfony.md>)

### AI overview

SymfonyCon Warsaw 2026 will take place in Poland on November 26-27, with talks across three parallel tracks and related community events. The announcement highlights a talk about PHP supply-chain security changes made after attacks involving Composer and Packagist, including malware detection, transparency logging, dependency policies, immutable releases, release-age settings, maintainer MFA status, and ownership controls.

### Source excerpt

Get ready to connect with the global Symfony community! SymfonyCon Warsaw 2026 is landing in Poland, on November 26-27. We are bringing you two days of inspiring talks across 3 parallel tracks, alongside plenty of networking opportunities and vibrant...

## CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks

DevFeed: [CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks](<https://devfeed.tech/articles/crowdstrike-extends-endpoint-security-to-stop-software-supply-chain-attacks-8305.md>)

Original publisher: [Read original article](<https://www.crowdstrike.com/en-us/blog/crowdstrike-extends-endpoint-security-to-stop-supply-chain-attacks/>)

Author: Anne Aarness - Chris Prall

Published: 2026-09-12T11:17:51.295154Z

Content type: article

Language: en

Sources: [Blog](<https://devfeed.tech/sources/blog.md>)

Topics: [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Software](<https://devfeed.tech/topics/software.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [codex](<https://devfeed.tech/topics/codex.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [codex](<https://devfeed.tech/tags/codex.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [developer](<https://devfeed.tech/tags/developer.md>), [developers](<https://devfeed.tech/tags/developers.md>), [development](<https://devfeed.tech/tags/development.md>), [endpoint-security-xdr](<https://devfeed.tech/tags/endpoint-security-xdr.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-packages](<https://devfeed.tech/tags/open-source-packages.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

The article describes CrowdStrike's Real-Time Supply Chain Attack Protection, embedded in the Falcon sensor, which detects and blocks malicious open-source packages before their code executes on enterprise endpoints. It explains how AI-assisted and agentic applications have expanded software supply chain risk beyond developer workstations to endpoints across the organization.

### Source excerpt

Real-Time Supply Chain Attack Protection, embedded into the Falcon sensor, blocks malicious open-source packages at download to protect the endpoint.

## LTM Builds a Lightwell Remediation Services Practice Around IBM and Red Hat's $5B Open-Source Program

DevFeed: [LTM Builds a Lightwell Remediation Services Practice Around IBM and Red Hat's $5B Open-Source Program](<https://devfeed.tech/articles/ltm-builds-a-lightwell-remediation-services-practice-around-ibm-and-red-hat-s-5b-open-source-program-12366.md>)

Original publisher: [Read original article](<https://www.storagereview.com/news/ltm-builds-a-lightwell-remediation-services-practice-around-ibm-and-red-hats-5b-open-source-program>)

Author: Harold Fritts

Published: 2026-09-11T16:35:51Z

Content type: news

Language: en

Sources: [StorageReview.com](<https://devfeed.tech/sources/storagereview-com.md>)

Topics: [ibm](<https://devfeed.tech/topics/ibm.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [ibm](<https://devfeed.tech/tags/ibm.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [red-hat](<https://devfeed.tech/tags/red-hat.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

LTM is developing a remediation services practice around IBM and Red Hat's Lightwell program, which provides AI-generated, vendor-validated fixes for open-source software vulnerabilities. The offering is intended to help customers plan, prioritize, test, validate, and deploy patches at scale.

### Source excerpt

LTM, the Larsen & Toubro Group services company that was LTIMindtree until its February rebrand, is building a Lightwell remediation services practice around the $5 billion IBM and Red Hat program for securing open-source software with AI-generated, vendor-validated fixes. IBM's clearinghouse produces validated, production-ready patches for open-source dependencies; LTM's job is getting them into customer The post LTM Builds a Lightwell Remediation Services Practice Around IBM and Red Hat's $5B Open-Source Program appeared first on StorageReview.com.

## How OSPOs Are Preparing Organizations for the EU Cyber Resilience Act

DevFeed: [How OSPOs Are Preparing Organizations for the EU Cyber Resilience Act](<https://devfeed.tech/articles/how-ospos-are-preparing-organizations-for-the-eu-cyber-resilience-act-14497.md>)

Original publisher: [Read original article](<https://www.linuxfoundation.org/blog/how-ospos-are-preparing-organizations-for-the-eu-cyber-resilience-act>)

Author: andrewb@proximabiz.com (The Linux Foundation)

Published: 2026-09-09T19:11:24Z

Content type: article

Language: en

Sources: [Linux Foundation - Blog](<https://devfeed.tech/sources/linux-foundation-blog.md>)

Topics: [cyber resilience act](<https://devfeed.tech/topics/cyber-resilience-act.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [eu](<https://devfeed.tech/tags/eu.md>), [linux-foundation](<https://devfeed.tech/tags/linux-foundation.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openssf](<https://devfeed.tech/tags/openssf.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This Linux Foundation post explains how Open Source Program Offices can help organizations prepare for the EU Cyber Resilience Act, including identifying affected products and dependencies, coordinating legal, security, engineering and procurement teams, and responding to vulnerability and incident reporting obligations.

### Source excerpt

For organizations offering products with digital elements in the EU, the next major Cyber Resilience Act (CRA) deadline arrives on 11 September 2026. From that date, organizations covered by the reporting obligations must be ready to assess actively exploited vulnerabilities and severe security incidents, coordinate an internal response and submit notifications within the required timelines.

## How financial services companies can modernize their software supply chain

DevFeed: [How financial services companies can modernize their software supply chain](<https://devfeed.tech/articles/how-financial-services-companies-can-modernize-their-software-supply-chain-13089.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-financial-services-companies-can-modernize-their-software-supply-chain>)

Published: 2026-09-04T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [financial-services](<https://devfeed.tech/tags/financial-services.md>), [legacy](<https://devfeed.tech/tags/legacy.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article argues that financial services organizations should modernize software supply chain security while preserving business-critical systems. It explains that legacy infrastructure, regulatory obligations, and downtime concerns have encouraged deferred vulnerability remediation, but AI-assisted exploitation is making that risk increasingly dangerous.

### Source excerpt

Modernize your financial software supply chain without disrupting critical systems. See how trusted open source reduces risk without major migrations.

## What it took to reach 1 billion build manifests

DevFeed: [What it took to reach 1 billion build manifests](<https://devfeed.tech/articles/what-it-took-to-reach-1-billion-build-manifests-13318.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/what-it-took-to-reach-1-billion-build-manifests>)

Published: 2026-09-03T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [NumPy](<https://devfeed.tech/topics/numpy.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-factory](<https://devfeed.tech/tags/chainguard-factory.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [go](<https://devfeed.tech/tags/go.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

Chainguard describes how it doubled container build output from 500 million to more than 1 billion manifests in six months. The article explains how Chainguard Factory and Chainguard OS support continuous rebuilds, while using source builds, SLSA Level 3 provenance, Sigstore signatures, and full SBOMs.

### Source excerpt

Chainguard doubled its container build output in six months. Learn how Factory 2.0 uses AI and reconciliation to rebuild secure software at scale.

## When AI skills become supply-chain dependencies

DevFeed: [When AI skills become supply-chain dependencies](<https://devfeed.tech/articles/when-ai-skills-become-supply-chain-dependencies-38854.md>)

Original publisher: [Read original article](<https://building.nubank.com/when-ai-skills-become-supply-chain-dependencies-2/>)

Author: Nubank Editorial

Published: 2026-09-02T16:47:57Z

Content type: article

Language: en

Sources: [Nubank](<https://devfeed.tech/sources/nubank.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Development](<https://devfeed.tech/topics/development.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-research](<https://devfeed.tech/tags/ai-research.md>), [developer](<https://devfeed.tech/tags/developer.md>), [development](<https://devfeed.tech/tags/development.md>), [product-security](<https://devfeed.tech/tags/product-security.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

Nubank describes how AI skills and related components are expanding the software supply chain. Its security team reviewed more than 2,000 AI skills before distribution and argues that security controls must evolve as AI becomes part of the developer toolchain.

### Source excerpt

How Nubank vetted 2,000+ AI skills before distribution, building security into the developer workflow without turning safety into a separate gate The post When AI skills become supply-chain dependencies appeared first on Building Nubank.

## OpenClaw went viral. Meet the maintainers building and securing it.

DevFeed: [OpenClaw went viral. Meet the maintainers building and securing it.](<https://devfeed.tech/articles/openclaw-went-viral-meet-the-maintainers-building-and-securing-it-84.md>)

Original publisher: [Read original article](<https://github.blog/open-source/maintainers/openclaw-went-viral-meet-the-maintainers-building-and-securing-it/>)

Author: Gregg Cochran

Published: 2026-08-27T16:00:00Z

Content type: article

Language: en

Sources: [GitHub Engineering](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [pull-requests](<https://devfeed.tech/topics/pull-requests.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Code review](<https://devfeed.tech/topics/code-review.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code](<https://devfeed.tech/tags/code.md>), [contributors](<https://devfeed.tech/tags/contributors.md>), [developers](<https://devfeed.tech/tags/developers.md>), [development](<https://devfeed.tech/tags/development.md>), [github](<https://devfeed.tech/tags/github.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>), [pull-request](<https://devfeed.tech/tags/pull-request.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [review](<https://devfeed.tech/tags/review.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

OpenClaw maintainers discuss the project's rapid growth, the resulting flood of pull requests, contributor trust, code review, software supply chain risks, and security. They describe welcoming contributions from first-time contributors, non-developers, and people using AI agents while refining promising changes.

### Source excerpt

OpenClaw is the fastest-growing project in GitHub history. Peter Steinberger and several maintainers share what they learned in the project's first six months. The post OpenClaw went viral. Meet the maintainers building and securing it. appeared first on The GitHub Blog.

## Moving from Minimus to Docker Hardened Images

DevFeed: [Moving from Minimus to Docker Hardened Images](<https://devfeed.tech/articles/moving-from-minimus-to-docker-hardened-images-4590.md>)

Original publisher: [Read original article](<https://www.docker.com/blog/moving-from-minimus-to-docker-hardened-images/>)

Author: Vishrut Iyengar

Published: 2026-08-25T22:27:06Z

Content type: article

Language: en

Sources: [Docker](<https://devfeed.tech/sources/docker.md>)

Topics: [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>), [migration](<https://devfeed.tech/topics/migration.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Docker Hub](<https://devfeed.tech/topics/docker-hub.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Debian](<https://devfeed.tech/topics/debian.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [apache](<https://devfeed.tech/tags/apache.md>), [ci](<https://devfeed.tech/tags/ci.md>), [community](<https://devfeed.tech/tags/community.md>), [debian](<https://devfeed.tech/tags/debian.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-hardened-images](<https://devfeed.tech/tags/docker-hardened-images.md>), [docker-hub](<https://devfeed.tech/tags/docker-hub.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [guide](<https://devfeed.tech/tags/guide.md>), [migration](<https://devfeed.tech/tags/migration.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [products](<https://devfeed.tech/tags/products.md>), [security](<https://devfeed.tech/tags/security.md>), [solutions](<https://devfeed.tech/tags/solutions.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Docker explains how Minimus customers can migrate to Docker Hardened Images before the Minimus registry goes offline on October 22, 2026. The article highlights the 60-day maintenance window, free migration assistance, DHI's open-source Apache 2.0 catalog, and a drop-in migration process centered on updating Dockerfile FROM lines.

### Source excerpt

The Minimus registry goes offline on October 22. Here is the migration path, the free help Docker is offering, and where to start.

## Security Hub Extended adds Supply Chain Security as its tenth category

DevFeed: [Security Hub Extended adds Supply Chain Security as its tenth category](<https://devfeed.tech/articles/security-hub-extended-adds-supply-chain-security-as-its-tenth-category-4690.md>)

Original publisher: [Read original article](<https://aws.amazon.com/blogs/security/security-hub-extended-adds-supply-chain-security-as-its-tenth-category/>)

Author: Michael Fuller

Published: 2026-08-18T17:04:28Z

Content type: news

Language: en

Sources: [AWS Security Blog](<https://devfeed.tech/sources/aws-security-blog.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>)

Tags: [amazon-web-services-aws](<https://devfeed.tech/tags/amazon-web-services-aws.md>), [announcements](<https://devfeed.tech/tags/announcements.md>), [aws](<https://devfeed.tech/tags/aws.md>), [aws-security-hub](<https://devfeed.tech/tags/aws-security-hub.md>), [black-hat](<https://devfeed.tech/tags/black-hat.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [foundational-100](<https://devfeed.tech/tags/foundational-100.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [partners](<https://devfeed.tech/tags/partners.md>), [payment](<https://devfeed.tech/tags/payment.md>), [pricing](<https://devfeed.tech/tags/pricing.md>), [security](<https://devfeed.tech/tags/security.md>), [security-blog](<https://devfeed.tech/tags/security-blog.md>), [security-identity-compliance](<https://devfeed.tech/tags/security-identity-compliance.md>), [software](<https://devfeed.tech/tags/software.md>), [streaming](<https://devfeed.tech/tags/streaming.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

AWS Security Hub Extended adds Supply Chain Security as its tenth category, with Chainguard and Socket as curated partners. The article frames software supply-chain risk as an enterprise security concern and describes pay-as-you-go and private-offer procurement options.

### Source excerpt

Since February, we've grown AWS Security Hub Extended from 14 curated partners across 9 categories to 23 partners across 10. At Black Hat this month, 14 of those partners were at the Amazon Web Services (AWS) booth demoing live. Four of those partners delivered theater talks and ten were featured on SecurityLive streaming. We hosted [...]

## Proven, not promised: Chainguard Containers achieves SLSA Build Level 3

DevFeed: [Proven, not promised: Chainguard Containers achieves SLSA Build Level 3](<https://devfeed.tech/articles/proven-not-promised-chainguard-containers-achieves-slsa-build-level-3-13206.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/proven-not-promised-chainguard-containers-achieves-slsa-build-level-3>)

Published: 2026-08-17T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [signing](<https://devfeed.tech/tags/signing.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

Chainguard says Coalfire independently assessed the Chainguard Containers build and release system as meeting SLSA Build Level 3 requirements. The article describes hardened, isolated builds, separately managed signing, provenance generation, and signed SBOMs for releases.

### Source excerpt

Coalfire independently assessed Chainguard Containers at SLSA Build Level 3, validating hardened builds, provenance, and supply chain integrity.

## ChainDrop npm Worm: Why SLSA Provenance Wasn't Enough

DevFeed: [ChainDrop npm Worm: Why SLSA Provenance Wasn't Enough](<https://devfeed.tech/articles/chaindrop-npm-worm-why-slsa-provenance-wasn-t-enough-13377.md>)

Original publisher: [Read original article](<https://www.harness.io/blog/chaindrop-npm-worm-valid-provenance>)

Author: Harness Team

Published: 2026-08-10T00:00:00Z

Content type: article

Language: en

Sources: [Harness Blog](<https://devfeed.tech/sources/harness-blog.md>)

Topics: [ChainDrop](<https://devfeed.tech/topics/chaindrop.md>), [npm](<https://devfeed.tech/topics/npm.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [chaindrop](<https://devfeed.tech/tags/chaindrop.md>), [ci](<https://devfeed.tech/tags/ci.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [least-privilege](<https://devfeed.tech/tags/least-privilege.md>), [malware](<https://devfeed.tech/tags/malware.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-worm](<https://devfeed.tech/tags/npm-worm.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [security](<https://devfeed.tech/tags/security.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [worm](<https://devfeed.tech/tags/worm.md>)

### AI overview

The ChainDrop npm worm compromised hundreds of packages while retaining valid SLSA provenance, demonstrating that build attestations do not guarantee source integrity. The article explains the worm's propagation, credential theft, persistence mechanisms, and recommended defenses, including source governance, dependency controls, least-privilege identities, policy gates, and runtime evidence.

### Source excerpt

ChainDrop poisoned hundreds of npm packages while retaining valid provenance. Learn why signed builds need source governance, policy gates, and runtime evidence | Blog

## Why AI-assisted attacks made software supply chain security its own category

DevFeed: [Why AI-assisted attacks made software supply chain security its own category](<https://devfeed.tech/articles/why-ai-assisted-attacks-made-software-supply-chain-security-its-own-category-13324.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/why-ai-assisted-attacks-made-software-supply-chain-security-its-own-category>)

Published: 2026-08-03T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Agent Skills](<https://devfeed.tech/topics/agent-skills.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>)

Tags: [agent-skills](<https://devfeed.tech/tags/agent-skills.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-assisted-attacks](<https://devfeed.tech/tags/ai-assisted-attacks.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [containers](<https://devfeed.tech/tags/containers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

The article argues that AI has changed the economics and speed of software supply chain attacks, making software supply chain security a distinct category requiring dedicated tooling, budgets, and strategy. It describes how AI benefits defenders and attackers, while agents accelerate dependency adoption and introduce risks through artifacts such as agent skills.

### Source excerpt

Software supply chain security is now its own category. Discover why AI is driving a shift toward trusted, secure-by-default open source.

## Introducing Deputy: Better signal and control for software supply chains

DevFeed: [Introducing Deputy: Better signal and control for software supply chains](<https://devfeed.tech/articles/introducing-deputy-better-signal-and-control-for-software-supply-chains-35886.md>)

Original publisher: [Read original article](<https://temporal.io/blog/introducing-deputy>)

Author: Kent Gruber

Published: 2026-08-03T00:00:00Z

Content type: release

Language: en

Sources: [Temporal Blog](<https://devfeed.tech/sources/temporal-blog.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [cli](<https://devfeed.tech/tags/cli.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [software](<https://devfeed.tech/tags/software.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [temporal-voices](<https://devfeed.tech/tags/temporal-voices.md>)

### AI overview

Temporal introduces Deputy, an open-source, CLI-first security toolchain for inventorying, scanning, triaging, and controlling dependencies across repositories, container images, VM disk images, SBOMs, and other targets. It provides a customizable policy layer for local use, CI, and download-time controls.

### Source excerpt

Meet Deputy, Temporal's open-source, CLI-first toolchain for inventorying, scanning, triaging, and controlling dependencies across your supply chain.

## Codename One Adds On-Device AI and Loopback MCP Support

DevFeed: [Codename One Adds On-Device AI and Loopback MCP Support](<https://devfeed.tech/articles/on-device-ai-and-mcp-on-every-port-19421.md>)

Original publisher: [Read original article](<https://www.codenameone.com/blog/on-device-ai-mcp-loopback/>)

Author: Shai Almog

Published: 2026-08-02T00:00:00Z

Content type: release

Language: en

Sources: [CodeName One](<https://devfeed.tech/sources/codename-one.md>)

Topics: [On-device AI](<https://devfeed.tech/topics/on-device-ai.md>), [Model Context Protocol](<https://devfeed.tech/topics/model-context-protocol.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [LiteRT](<https://devfeed.tech/topics/litert.md>), [Inference](<https://devfeed.tech/topics/inference.md>), [Mobile](<https://devfeed.tech/topics/mobile.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>)

Tags: [applications](<https://devfeed.tech/tags/applications.md>), [inference](<https://devfeed.tech/tags/inference.md>), [litert](<https://devfeed.tech/tags/litert.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [on-device](<https://devfeed.tech/tags/on-device.md>), [on-device-ai](<https://devfeed.tech/tags/on-device-ai.md>), [tensorflow-lite](<https://devfeed.tech/tags/tensorflow-lite.md>)

### AI overview

Codename One has added on-device vision, language, and LiteRT inference to its core, alongside a guarded loopback MCP transport for inspecting and operating applications. The article explains platform support, asynchronous OCR, model sessions, secure model downloads, and privacy limitations of local inference.

### Source excerpt

Codename One now exposes on-device vision, language, and LiteRT inference in the core, while a guarded loopback MCP transport lets an LLM inspect and drive real applications.

## pnpm vs. npm: Which package manager should you use?

DevFeed: [pnpm vs. npm: Which package manager should you use?](<https://devfeed.tech/articles/pnpm-vs-npm-which-package-manager-should-you-use-4354.md>)

Original publisher: [Read original article](<https://blog.logrocket.com/pnpm-vs-npm-which-package-manager-use/>)

Author: Chinwike Maduabuchi

Published: 2026-07-28T13:00:17Z

Content type: article

Language: en

Sources: [LogRocket Blog](<https://devfeed.tech/sources/logrocket-blog.md>)

Topics: [npm](<https://devfeed.tech/topics/npm.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Yarn](<https://devfeed.tech/topics/yarn.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [article](<https://devfeed.tech/tags/article.md>), [dev](<https://devfeed.tech/tags/dev.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article compares npm and pnpm as JavaScript package managers, focusing on security defaults, disk usage, dependency strictness, workspace behavior, and software supply chain risk. It explains how pnpm's content-addressable store and linked dependencies improve efficiency while stricter installation policies can make migrations more demanding.

### Source excerpt

Compare pnpm and npm across security defaults, disk usage, dependency strictness, and workspace policy to decide which package manager fits your project. The post pnpm vs. npm: Which package manager should you use? appeared first on LogRocket Blog.

## How to protect an npm package from supply chain attacks

DevFeed: [How to protect an npm package from supply chain attacks](<https://devfeed.tech/articles/the-secure-way-to-release-an-npm-package-in-2026-19792.md>)

Original publisher: [Read original article](<https://evilmartians.com/chronicles/the-secure-way-to-release-an-npm-package>)

Author: Travis Turner (richardturner@evilmartians.com)

Published: 2026-07-28T00:00:00Z

Content type: tutorial

Language: en

Sources: [Evil Martians](<https://devfeed.tech/sources/evil-martians.md>)

Topics: [npm](<https://devfeed.tech/topics/npm.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [ci](<https://devfeed.tech/topics/ci.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [ci](<https://devfeed.tech/tags/ci.md>), [developer-community](<https://devfeed.tech/tags/developer-community.md>), [dx](<https://devfeed.tech/tags/dx.md>), [github](<https://devfeed.tech/tags/github.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [monorepo](<https://devfeed.tech/tags/monorepo.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [performance-scale](<https://devfeed.tech/tags/performance-scale.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

This tutorial explains how to protect npm packages from supply chain attacks. It covers Trusted Publishers, publishing restrictions, organization-wide 2FA, GitHub tag controls, pinned CI actions, CI security linting, cooldowns for new versions, and staged-release approval.

### Source excerpt

How to protect your npm package from being stolen in a supply chain attack and improve its position in security ratings

## Introducing AI-powered container standardization

DevFeed: [Introducing AI-powered container standardization](<https://devfeed.tech/articles/introducing-ai-powered-container-standardization-22574.md>)

Original publisher: [Read original article](<https://medium.com/capital-one-tech/introducing-ai-powered-container-standardization-2f9314cde883?source=rss----3db3a67cb648---4>)

Author: Capital One Tech

Published: 2026-07-27T15:04:11Z

Content type: article

Language: en

Sources: [Capital One Tech](<https://devfeed.tech/sources/capital-one-tech.md>)

Topics: [Containers](<https://devfeed.tech/topics/containers.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [sdlc](<https://devfeed.tech/topics/sdlc.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [containers](<https://devfeed.tech/tags/containers.md>), [requirements](<https://devfeed.tech/tags/requirements.md>), [security](<https://devfeed.tech/tags/security.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [software-engineering](<https://devfeed.tech/tags/software-engineering.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article presents AI-powered container standardization as an approach to automate vulnerability detection, prioritization, remediation, testing, and patch deployment. It recommends avoiding exposure through curated base images and vetted dependencies, then automating ongoing remediation within the software development life cycle.

### Source excerpt

AI-powered container standardization enables hands-free security remediation without sacrificing development velocity. In today's cloud-native world, containers have become the foundation of modern software delivery. Managing container security at scale can present significant challenges, thousands of vulnerabilities to track, manual remediation processes, inconsistent base images across teams and compliance requirements that slow everything down. AI-powered container standardization is a comprehensive approach that leverages artificial intelligence (AI) to automate vulnerability detection, prioritization and remediation across your entire container ecosystem. This transformative solution significantly reduces the manual toil traditionally associated with keeping containers secure and compliant. Development teams can focus on building features while the system automatically identifies vulnerabilities, generates fixes, tests changes and deploys patches, minimizing human intervention for routine updates. This approach simplifies the coordination of vulnerability remediation across hundreds of teams while ensuring that security and compliance are embedded throughout the software life cycle. Organizations can empower their developers to focus on innovation rather than patching, resulting in faster releases, stronger security and more productive engineering teams. The strategic framework: avoid and automate Our strategy for managing vulnerabilities focuses on two core principles: avoiding exposure and automating remediation, with governance baked into the software development life cycle. Avoid: Secure the foundation to minimize risk entering your environment. The most effective vulnerability remediation happens prior to the vulnerability reaching your digital ecosystems. By controlling what enters the software supply chain through curated base images and vetted dependencies/packages, you dramatically reduce the attack surface before code ever runs in production. This inc

## Best GitHub Actions Alternatives in 2026

DevFeed: [Best GitHub Actions Alternatives in 2026](<https://devfeed.tech/articles/best-github-actions-alternatives-in-2026-20418.md>)

Original publisher: [Read original article](<https://semaphore.io/blog/best-github-actions-alternatives-in-2026>)

Author: Pete Miloravac

Published: 2026-07-23T12:51:23Z

Content type: article

Language: en

Sources: [Semaphore Engineering](<https://devfeed.tech/sources/semaphore-engineering.md>)

Topics: [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [alternatives](<https://devfeed.tech/tags/alternatives.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [compare](<https://devfeed.tech/tags/compare.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [guide](<https://devfeed.tech/tags/guide.md>), [outage](<https://devfeed.tech/tags/outage.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

A 2026 guide compares alternatives to GitHub Actions and discusses why some teams are reconsidering it, citing a major outage, a supply-chain attack affecting thousands of repositories, pricing and runner-management concerns, and log usability issues.

### Source excerpt

GitHub Actions became the default CI/CD choice for millions of repositories simply because it's built into GitHub. But "default" and "best" are not the same thing -- and in 2026, the gap between the two has gotten harder to ignore. A ten-hour outage in July, a supply-chain attack that backdoored over 5,500 repositories in May, [...] The post Best GitHub Actions Alternatives in 2026 appeared first on Semaphore.

## Understanding platform engineering's role in staying compliant with the EU's CRA

DevFeed: [Understanding platform engineering's role in staying compliant with the EU's CRA](<https://devfeed.tech/articles/understanding-platform-engineering-s-role-in-staying-compliant-with-the-eu-s-cra-12256.md>)

Original publisher: [Read original article](<https://platformengineering.org/blog/understanding-platform-engineering-s-role-in-staying-compliant-with-the-eus-cra>)

Author: Nigel Douglas

Published: 2026-07-23T05:40:01Z

Content type: article

Language: en

Sources: [Platform Engineering Blog](<https://devfeed.tech/sources/platform-engineering-blog.md>)

Topics: [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [compliance](<https://devfeed.tech/tags/compliance.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [eu](<https://devfeed.tech/tags/eu.md>), [idp](<https://devfeed.tech/tags/idp.md>), [incident](<https://devfeed.tech/tags/incident.md>), [platform](<https://devfeed.tech/tags/platform.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [policy](<https://devfeed.tech/tags/policy.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

The article explains how platform engineering can operationalize compliance with the EU's Cyber Resilience Act by embedding secure-by-default practices, automated SBOMs, and rapid incident reporting into an Internal Development Platform. It also outlines CRA compliance milestones and manufacturer responsibilities, including vulnerability management and security updates.

### Source excerpt

The EU's Cyber Resilience Act (CRA) mandates secure software by design. Discover how platform engineering operationalizes compliance by embedding secure-by-default standards, automated SBOMs, and rapid incident reporting into your Internal Development Platform (IDP). This approach transforms compliance into a frictionless golden path

## Why repository-centric security still needs an artifact access control plane

DevFeed: [Why repository-centric security still needs an artifact access control plane](<https://devfeed.tech/articles/why-repository-centric-security-still-needs-an-artifact-access-control-plane-12282.md>)

Original publisher: [Read original article](<https://platformengineering.org/blog/why-repository-centric-security-still-needs-an-artifact-access-control-plane>)

Author: Adrian Herrera

Published: 2026-07-23T05:40:01Z

Content type: article

Language: en

Sources: [Platform Engineering Blog](<https://devfeed.tech/sources/platform-engineering-blog.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [iac-security](<https://devfeed.tech/topics/iac-security.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [infrastructure-as-code](<https://devfeed.tech/tags/infrastructure-as-code.md>), [security](<https://devfeed.tech/tags/security.md>), [security-policies](<https://devfeed.tech/tags/security-policies.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

The article explains that repository-centric security controls can leave gaps because dependency access is distributed across CI runners, ephemeral build agents, public registries, developer tooling, and automation. It argues for an artifact access control plane, including Virtual Registries, to enforce security policies inline across CI/CD execution paths, complementing repository-based vulnerability scanning, license analysis, dependency governance, and remediation.

### Source excerpt

Repository security gaps: Distributed dependency access bypasses centralized analysis. Virtual Registries offer the critical inline control plane to enforce artifact security policies across your CI/CD pipeline.

## Scaling Kubernetes governance: A platform engineer's guide to Kyverno and CEL

DevFeed: [Scaling Kubernetes governance: A platform engineer's guide to Kyverno and CEL](<https://devfeed.tech/articles/scaling-kubernetes-governance-a-platform-engineer-s-guide-to-kyverno-and-cel-12220.md>)

Original publisher: [Read original article](<https://platformengineering.org/blog/scaling-kubernetes-governance-a-platform-engineers-guide-to-kyverno-and-cel>)

Author: Koray Oksay

Published: 2026-07-23T05:40:01Z

Content type: article

Language: en

Sources: [Platform Engineering Blog](<https://devfeed.tech/sources/platform-engineering-blog.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>), [Security](<https://devfeed.tech/topics/security.md>), [developer velocity](<https://devfeed.tech/topics/developer-velocity.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [YAML](<https://devfeed.tech/topics/yaml.md>), [opa](<https://devfeed.tech/topics/opa.md>), [rego](<https://devfeed.tech/topics/rego.md>)

Tags: [common-expression-language](<https://devfeed.tech/tags/common-expression-language.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [developer-velocity](<https://devfeed.tech/tags/developer-velocity.md>), [governance](<https://devfeed.tech/tags/governance.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [integration](<https://devfeed.tech/tags/integration.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kyverno](<https://devfeed.tech/tags/kyverno.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [platform](<https://devfeed.tech/tags/platform.md>), [policy](<https://devfeed.tech/tags/policy.md>), [security](<https://devfeed.tech/tags/security.md>), [security-policies](<https://devfeed.tech/tags/security-policies.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

A guide to using Kyverno and its Common Expression Language support for Kubernetes governance. It explains how platform engineering teams can enforce policies, automate resource changes, generate resources, verify image signatures, and maintain security and compliance while preserving developer velocity.

### Source excerpt

Kyverno with CEL support provides Policy-as-Code for Kubernetes governance. Enforce security, automate guardrails, and boost developer velocity for platform engineering teams.

## Announcing the State of Platform Engineering Report Vol 4

DevFeed: [Announcing the State of Platform Engineering Report Vol 4](<https://devfeed.tech/articles/announcing-the-state-of-platform-engineering-report-vol-4-12133.md>)

Original publisher: [Read original article](<https://platformengineering.org/blog/announcing-the-state-of-platform-engineering-vol-4>)

Author: Sam Barlien

Published: 2026-07-23T05:40:01Z

Content type: article

Language: en

Sources: [Platform Engineering Blog](<https://devfeed.tech/sources/platform-engineering-blog.md>)

Topics: [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [GPU](<https://devfeed.tech/topics/gpu.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [MLOps](<https://devfeed.tech/topics/mlops.md>), [finops](<https://devfeed.tech/topics/finops.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-ml](<https://devfeed.tech/tags/ai-ml.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [mlops](<https://devfeed.tech/tags/mlops.md>), [platform](<https://devfeed.tech/tags/platform.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [platforms](<https://devfeed.tech/tags/platforms.md>), [report](<https://devfeed.tech/tags/report.md>), [scale](<https://devfeed.tech/tags/scale.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [speed](<https://devfeed.tech/tags/speed.md>)

### AI overview

The State of Platform Engineering Report Volume 4 presents platform engineering as a foundational discipline for modern enterprises. Based on insights from 518 engineers, it describes a shift from the cloud-native era to an AI-native era, emphasizing "shifting down," AI-powered platforms, platforms for AI, specialized GPU infrastructure, governance, and MLOps requirements.

### Source excerpt

Insights from over 500 engineers. Explore the shift to 'AI-native,' the 'dual mandate,' 'shifting down,' and key trends for 2026.

## Securing the Agent DLC: A Practical Guide

DevFeed: [Securing the Agent DLC: A Practical Guide](<https://devfeed.tech/articles/securing-the-agent-dlc-a-practical-guide-13467.md>)

Original publisher: [Read original article](<https://www.harness.io/blog/securing-the-agent-dlc>)

Author: Rahul Sood

Published: 2026-07-21T00:00:00Z

Content type: article

Language: en

Sources: [Harness Blog](<https://devfeed.tech/sources/harness-blog.md>)

Topics: [Development](<https://devfeed.tech/topics/development.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Firewall](<https://devfeed.tech/topics/firewall.md>), [Model Context Protocol](<https://devfeed.tech/topics/model-context-protocol.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [observability](<https://devfeed.tech/tags/observability.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

Harness presents an Agent Development Lifecycle security approach for AI agents, covering design-time scanning, AI bills of materials, testing, discovery, firewall controls, and runtime observability. The article argues that agents require security practices adapted to their dynamic tool, model, and API connections.

### Source excerpt

Harness secures AI agents from development to runtime with AIBOM, AI testing, discovery, firewall, and observability across the Agent DLC. | Blog

[Next page](<https://devfeed.tech/topics/supply-chain-security.md?cursor=WyIyMDI2LTA3LTIxVDAwOjAwOjAwKzAwOjAwIiwgIjAxYTQyNGU5LTBhZGItNDU3ZS1iMmYzLTdjNGRkYjUzYTIwNyJd>)