FINOS Announces Intent to Form OSERA, a Bank-Led Alliance to Mutualize Open Source Patching
Five banks piloted a shared open source patching alliance; FINOS says AI-accelerated vulnerability discovery makes mutualized fixes urgent.
Signal
11 articles covering "supply chain security"
Five banks piloted a shared open source patching alliance; FINOS says AI-accelerated vulnerability discovery makes mutualized fixes urgent.
Dependabot now waits three days before proposing new dependency versions by default. GitHub says the delay keeps freshly compromised releases out of update pull requests; security updates are exempt and repositories can opt out.
npm v12 disables install scripts, Git dependencies, and remote-URL dependencies by default, closing the execution path several npm worms exploited over the past year.
GitHub's new License Compliance feature enters public preview, letting Enterprise Cloud customers with GitHub Advanced Security block pull requests that add dependencies violating license policy.
Bundler 4.0.13's cooldown filter excludes brand-new gem versions from dependency resolution to blunt supply-chain attacks that exploit the minutes after a malicious release.
GitHub's npm registry makes staged publishing generally available: packages must pass a human-approved, 2FA-gated queue before consumers can install them.
The new public-preview command installs, pins, updates, and publishes portable skills for Copilot, Claude Code, Cursor, Codex, Gemini CLI, and Antigravity — with git-backed provenance and an explicit prompt-injection warning.
Canonical has joined the Rust Foundation at the Gold membership tier, pledging $150,000 annually to support language governance and ecosystem security as Ubuntu 26.04 LTS prepares to ship with Rust-based coreutils and sudo by default.
The US and Japan enacted a critical minerals action plan on March 19 featuring price floors and four joint projects as neodymium prices doubled year-to-date and a $12 billion US strategic stockpile takes shape.
Check Point Research disclosed two CVEs in Anthropic's Claude Code that turned project configuration files into attack vectors, enabling remote code execution and API key exfiltration before users could approve a trust dialog.
IBM's annual threat index finds vulnerability exploitation now causes 40% of breaches, with 109 ransomware groups active and over 300,000 AI platform credentials stolen.