<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>devtake.dev — #supply-chain</title><description>Articles tagged supply-chain on devtake.dev.</description><link>https://devtake.dev/</link><language>en-us</language><item><title>Renault ditched rare-earth magnets in its EVs in 2012. China&apos;s export squeeze made that look smart</title><link>https://devtake.dev/article/electric-motors-no-rare-earths/</link><guid isPermaLink="true">https://devtake.dev/article/electric-motors-no-rare-earths/</guid><description>A Renault explainer on rare-earth-free EV motors hit Hacker News. Here&apos;s how electric cars run without the magnets China controls, and who&apos;s shipping them.</description><pubDate>Sat, 13 Jun 2026 13:45:00 GMT</pubDate><category>hardware</category><category>ev</category><category>hardware</category><category>china</category><category>supply-chain</category><category>sustainability</category><author>hiro-tanaka</author></item><item><title>Red Hat&apos;s npm namespace and Arch&apos;s AUR were both backdoored within two weeks of each other</title><link>https://devtake.dev/article/npm-registry-supply-chain-wave/</link><guid isPermaLink="true">https://devtake.dev/article/npm-registry-supply-chain-wave/</guid><description>A worm hijacked Red Hat&apos;s npm namespace, a rootkit spread through 1,500 Arch AUR packages, and a SOC 2-certified AI gateway shipped malware. Registries are under fire.</description><pubDate>Sat, 13 Jun 2026 12:45:00 GMT</pubDate><category>security</category><category>security</category><category>supply-chain</category><category>npm</category><category>open-source</category><category>malware</category><author>luca-reinhardt</author></item><item><title>One bad Host header bypassed auth in Starlette, the routing core under millions of AI agents</title><link>https://devtake.dev/article/ai-agents-package-rce-vulnerability/</link><guid isPermaLink="true">https://devtake.dev/article/ai-agents-package-rce-vulnerability/</guid><description>A flaw in Starlette, downloaded 325M times a week, let a single Host-header character bypass path-based auth across FastAPI, vLLM, and MCP servers.</description><pubDate>Mon, 08 Jun 2026 10:00:00 GMT</pubDate><category>security</category><category>security</category><category>supply-chain</category><category>ai-agents</category><category>mcp</category><category>cve-2026-48710</category><category>python</category><category>fastapi</category><author>luca-reinhardt</author></item><item><title>VS Code&apos;s webview sandbox leaks GitHub tokens that read and write every private repo</title><link>https://devtake.dev/article/vscode-zero-day-github-token-theft/</link><guid isPermaLink="true">https://devtake.dev/article/vscode-zero-day-github-token-theft/</guid><description>A disclosed VS Code zero-day lets one click on a malicious github.dev notebook steal a GitHub OAuth token with full read-write access to every private repo.</description><pubDate>Wed, 03 Jun 2026 13:15:00 GMT</pubDate><category>security</category><category>security</category><category>github</category><category>credential-theft</category><category>dev-tools</category><category>rce</category><category>supply-chain</category><category>oauth</category><author>luca-reinhardt</author></item><item><title>A browser SSD timing trick can fingerprint your browsing, and cookies won&apos;t stop it</title><link>https://devtake.dev/article/ssd-activity-browser-side-channel/</link><guid isPermaLink="true">https://devtake.dev/article/ssd-activity-browser-side-channel/</guid><description>Graz researchers built FROST, a browser side-channel that times SSD activity to guess which sites and apps you&apos;re running. Here&apos;s how it works and what helps.</description><pubDate>Wed, 03 Jun 2026 11:30:00 GMT</pubDate><category>web</category><category>privacy</category><category>security</category><category>web</category><category>browser-security</category><category>fingerprinting</category><category>side-channel</category><category>supply-chain</category><author>naomi-park</author></item><item><title>116,000 Minecraft PCs got infected by fake mods. The &apos;WeedHack&apos; stealer is free to anyone.</title><link>https://devtake.dev/article/minecraft-weedhack-malware/</link><guid isPermaLink="true">https://devtake.dev/article/minecraft-weedhack-malware/</guid><description>McAfee says a free malware-as-a-service stealer called WeedHack has hit 116,000+ Minecraft systems via fake mods and cheats. Here&apos;s what it grabs and how to clean up.</description><pubDate>Wed, 03 Jun 2026 11:00:00 GMT</pubDate><category>gaming</category><category>gaming</category><category>minecraft</category><category>malware</category><category>security</category><category>credential-theft</category><category>infostealer</category><category>supply-chain</category><author>hiro-tanaka</author></item><item><title>GitHub banned the researcher dropping Windows zero-days. The code was already mirrored everywhere.</title><link>https://devtake.dev/article/github-bans-researcher-windows-zero-day/</link><guid isPermaLink="true">https://devtake.dev/article/github-bans-researcher-windows-zero-day/</guid><description>GitHub wiped Nightmare-Eclipse&apos;s account on May 23 after weeks of unpatched Windows exploits. The ban reopened the oldest fight in security: who decides what research gets hosted?</description><pubDate>Fri, 29 May 2026 06:50:00 GMT</pubDate><category>security</category><category>security</category><category>github</category><category>vulnerability-disclosure</category><category>zero-day</category><category>microsoft</category><category>windows</category><category>supply-chain</category><category>rce</category><author>luca-reinhardt</author></item><item><title>Anthropic&apos;s Glasswing logged 10,000 vulnerabilities in a month. Most are still waiting on a patch.</title><link>https://devtake.dev/article/anthropic-glasswing-deception-monitor/</link><guid isPermaLink="true">https://devtake.dev/article/anthropic-glasswing-deception-monitor/</guid><description>Anthropic says Project Glasswing&apos;s first month produced over 10,000 critical-and-high-severity vulns. Verification and patching is the limiting step.</description><pubDate>Sat, 23 May 2026 09:45:00 GMT</pubDate><category>ai</category><category>anthropic</category><category>claude-mythos</category><category>project-glasswing</category><category>security</category><category>ai-security</category><category>supply-chain</category><category>vulnerability-disclosure</category><author>dieter-morelli</author></item><item><title>GitHub&apos;s internal repos were breached. The attacker came in through a poisoned VS Code extension.</title><link>https://devtake.dev/article/github-internal-repos-breach-vscode-extension/</link><guid isPermaLink="true">https://devtake.dev/article/github-internal-repos-breach-vscode-extension/</guid><description>GitHub detected the intrusion on May 18 after a malicious VS Code extension compromised an employee&apos;s device. The attacker claims to have exfiltrated 3,800 internal repositories.</description><pubDate>Fri, 22 May 2026 10:15:00 GMT</pubDate><category>security</category><category>security</category><category>github</category><category>vscode</category><category>supply-chain</category><category>credential-theft</category><category>dev-tools</category><author>luca-reinhardt</author></item><item><title>A CISA contractor left GovCloud admin keys on public GitHub. The file was named &apos;Important AWS Tokens.txt&apos;.</title><link>https://devtake.dev/article/cisa-aws-govcloud-keys-github-leak/</link><guid isPermaLink="true">https://devtake.dev/article/cisa-aws-govcloud-keys-github-leak/</guid><description>GitGuardian found a public CISA repo with 844 MB of secrets, including AWS GovCloud admin keys. The repo sat open for six months.</description><pubDate>Thu, 21 May 2026 11:15:00 GMT</pubDate><category>security</category><category>security</category><category>cisa</category><category>github</category><category>supply-chain</category><category>credential-theft</category><category>aws</category><category>gitguardian</category><category>govcloud</category><author>luca-reinhardt</author></item><item><title>A bad command-line parser turned every claude-cli:// link into a remote shell</title><link>https://devtake.dev/article/claude-code-rce-deeplink-cve/</link><guid isPermaLink="true">https://devtake.dev/article/claude-code-rce-deeplink-cve/</guid><description>Joernchen of 0day.click found a deeplink RCE in Claude Code. Anthropic shipped the fix in 2.1.118 the same week.</description><pubDate>Wed, 20 May 2026 09:15:00 GMT</pubDate><category>security</category><category>security</category><category>anthropic</category><category>claude-code</category><category>rce</category><category>ai-security</category><category>supply-chain</category><category>ai-agents</category><category>dev-tools</category><author>luca-reinhardt</author></item><item><title>Twin contractors deleted 96 federal databases in 56 minutes. One asked an AI how to clear the logs.</title><link>https://devtake.dev/article/akhter-twins-opexus-database-deletion/</link><guid isPermaLink="true">https://devtake.dev/article/akhter-twins-opexus-database-deletion/</guid><description>A federal jury convicted Sohaib Akhter on May 7 of wiping 96 government databases at Opexus. His twin Muneeb queried an AI: &apos;how do I clear system logs from SQL servers.&apos;</description><pubDate>Fri, 15 May 2026 09:00:00 GMT</pubDate><category>security</category><category>security</category><category>insider-threat</category><category>opexus</category><category>eeoc</category><category>credential-theft</category><category>foia</category><category>policy</category><category>supply-chain</category><author>luca-reinhardt</author></item><item><title>TanStack published its npm supply-chain postmortem. The attack chained three GitHub Actions flaws.</title><link>https://devtake.dev/article/tanstack-npm-supply-chain-postmortem/</link><guid isPermaLink="true">https://devtake.dev/article/tanstack-npm-supply-chain-postmortem/</guid><description>Attackers compromised 42 TanStack packages through a pull_request_target exploit, cache poisoning, and OIDC token theft. An external researcher caught it in 20 minutes.</description><pubDate>Tue, 12 May 2026 10:15:00 GMT</pubDate><category>security</category><category>security</category><category>supply-chain</category><category>npm</category><category>tanstack</category><category>github-actions</category><category>credential-theft</category><category>dev-tools</category><author>luca-reinhardt</author></item><item><title>Chinese proxy networks sell Claude API access at 90% off. They harvest every prompt that passes through.</title><link>https://devtake.dev/article/chinese-grey-market-claude-api-stolen-credentials/</link><guid isPermaLink="true">https://devtake.dev/article/chinese-grey-market-claude-api-stolen-credentials/</guid><description>A ChinaTalk investigation reveals how &apos;transfer stations&apos; resell Anthropic API access using stolen credentials, model substitution, and prompt harvesting.</description><pubDate>Sun, 10 May 2026 09:30:00 GMT</pubDate><category>ai</category><category>anthropic</category><category>claude</category><category>ai-security</category><category>credential-theft</category><category>china</category><category>supply-chain</category><category>ai-models</category><author>dieter-morelli</author></item><item><title>380,000 vibe-coded apps are sitting on the open web. 5,000 of them are leaking real data.</title><link>https://devtake.dev/article/vibe-coded-apps-expose-corporate-data/</link><guid isPermaLink="true">https://devtake.dev/article/vibe-coded-apps-expose-corporate-data/</guid><description>RedAccess found that AI coding tools like Lovable, Base44, and Replit default to public hosting, leaving medical records, bank internals, and corporate secrets indexed by Google.</description><pubDate>Sat, 09 May 2026 08:00:00 GMT</pubDate><category>security</category><category>security</category><category>ai-security</category><category>ai-agents</category><category>dev-tools</category><category>supply-chain</category><category>privacy</category><category>credential-theft</category><author>luca-reinhardt</author></item><item><title>ShinyHunters hit Canvas LMS for the second time. 275 million student records, 9,000 schools.</title><link>https://devtake.dev/article/instructure-canvas-breach-shinyhunters-275m/</link><guid isPermaLink="true">https://devtake.dev/article/instructure-canvas-breach-shinyhunters-275m/</guid><description>ShinyHunters breached Canvas LMS again, claiming 275 million records from 9,000 schools. Names, emails, student IDs, and private messages exposed.</description><pubDate>Fri, 08 May 2026 09:00:00 GMT</pubDate><category>security</category><category>security</category><category>data-breach</category><category>instructure</category><category>canvas</category><category>shinyhunters</category><category>education</category><category>supply-chain</category><category>credential-theft</category><author>luca-reinhardt</author></item><item><title>DAEMON Tools shipped a signed backdoor for almost a month. Kaspersky says one school in Russia got the second stage.</title><link>https://devtake.dev/article/daemon-tools-supply-chain-backdoor/</link><guid isPermaLink="true">https://devtake.dev/article/daemon-tools-supply-chain-backdoor/</guid><description>Kaspersky pinned a supply-chain attack on the DAEMON Tools installer dating to April 8. Thousands hit globally, dozens upgraded to a QUIC RAT implant via signed binaries.</description><pubDate>Wed, 06 May 2026 10:15:00 GMT</pubDate><category>security</category><category>security</category><category>supply-chain</category><category>daemon-tools</category><category>malware</category><category>kaspersky</category><category>quic-rat</category><category>code-signing</category><category>windows</category><author>luca-reinhardt</author></item><item><title>FCC just voted to bar Chinese labs from certifying US electronics. 75% of devices are tested there now.</title><link>https://devtake.dev/article/fcc-chinese-labs-electronics-certification-ban/</link><guid isPermaLink="true">https://devtake.dev/article/fcc-chinese-labs-electronics-certification-ban/</guid><description>Brendan Carr&apos;s FCC advanced the &apos;Bad Labs&apos; rule on April 30 in a 3-0 vote, kicking off a 60-90 day comment period. The rule covers 126 labs in China and Hong Kong.</description><pubDate>Sun, 03 May 2026 13:30:00 GMT</pubDate><category>policy</category><category>fcc</category><category>china</category><category>regulation</category><category>national-security</category><category>supply-chain</category><category>electronics</category><category>brendan-carr</category><category>hardware</category><author>clara-wexler</author></item><item><title>A DDoS knocked Ubuntu&apos;s update servers offline. The Copy Fail patch landed in the same 24-hour window.</title><link>https://devtake.dev/article/ubuntu-canonical-313-team-ddos-copyfail/</link><guid isPermaLink="true">https://devtake.dev/article/ubuntu-canonical-313-team-ddos-copyfail/</guid><description>The 313 Team flooded Canonical&apos;s infrastructure starting May 1, blocking apt updates and the Ubuntu security API just as admins needed both.</description><pubDate>Sat, 02 May 2026 09:30:00 GMT</pubDate><category>security</category><category>ubuntu</category><category>canonical</category><category>ddos</category><category>copy-fail</category><category>security</category><category>supply-chain</category><category>linux</category><author>luca-reinhardt</author></item><item><title>Mini Shai-Hulud hit PyTorch Lightning. The 11.6M-download PyPI package shipped a credential stealer.</title><link>https://devtake.dev/article/pytorch-lightning-pypi-compromise-mini-shai-hulud/</link><guid isPermaLink="true">https://devtake.dev/article/pytorch-lightning-pypi-compromise-mini-shai-hulud/</guid><description>Two malicious lightning releases hit PyPI on April 30. The 42-minute window was enough to ship an RSA-encrypted infostealer to ML developers worldwide.</description><pubDate>Sat, 02 May 2026 09:00:00 GMT</pubDate><category>security</category><category>pytorch-lightning</category><category>pypi</category><category>supply-chain</category><category>mini-shai-hulud</category><category>credential-theft</category><category>python</category><category>ml</category><category>security</category><author>luca-reinhardt</author></item><item><title>70 million domains had a no-password root bypass. cPanel rushed an emergency patch.</title><link>https://devtake.dev/article/cpanel-whm-auth-bypass-cve-2026-41940/</link><guid isPermaLink="true">https://devtake.dev/article/cpanel-whm-auth-bypass-cve-2026-41940/</guid><description>cPanel shipped fixes April 28 for a CVSS 9.8 auth bypass that walks attackers into shared-hosting panels with no password. WatchTowr says exploitation started before the patch.</description><pubDate>Fri, 01 May 2026 11:25:00 GMT</pubDate><category>security</category><category>security</category><category>cpanel</category><category>web-hosting</category><category>cve-2026-41940</category><category>auth-bypass</category><category>watchtowr</category><category>credential-theft</category><category>supply-chain</category><author>luca-reinhardt</author></item><item><title>&apos;Copy Fail&apos; lets a 732-byte script grab root on Ubuntu, RHEL, and SUSE. Patched April 29.</title><link>https://devtake.dev/article/copy-fail-linux-kernel-page-cache-root/</link><guid isPermaLink="true">https://devtake.dev/article/copy-fail-linux-kernel-page-cache-root/</guid><description>CVE-2026-31431 chains AF_ALG and splice() to write into the page cache of /usr/bin/su. Xint Code disclosed it on April 29, nine years after the bug shipped.</description><pubDate>Thu, 30 Apr 2026 09:15:00 GMT</pubDate><category>security</category><category>security</category><category>linux</category><category>cve-2026-31431</category><category>kernel</category><category>privilege-escalation</category><category>supply-chain</category><category>ubuntu</category><category>rhel</category><author>luca-reinhardt</author></item><item><title>Wiz found an RCE in GitHub&apos;s git-push pipeline. The patch shipped in six hours.</title><link>https://devtake.dev/article/github-rce-cve-2026-3854-wiz/</link><guid isPermaLink="true">https://devtake.dev/article/github-rce-cve-2026-3854-wiz/</guid><description>CVE-2026-3854 is a CVSS 8.7 RCE in GitHub&apos;s git-push pipeline. github.com fixed it within hours. 88% of Enterprise Server installs were still vulnerable at disclosure.</description><pubDate>Wed, 29 Apr 2026 09:05:00 GMT</pubDate><category>security</category><category>github</category><category>security</category><category>cve-2026-3854</category><category>rce</category><category>supply-chain</category><category>wiz</category><category>github-actions</category><category>dev-tools</category><author>luca-reinhardt</author></item><item><title>Another npm worm: CanisterWorm hits 16 Namastex packages and reaches PyPI on the same hop</title><link>https://devtake.dev/article/canisterworm-namastex-npm-pypi-supply-chain/</link><guid isPermaLink="true">https://devtake.dev/article/canisterworm-namastex-npm-pypi-supply-chain/</guid><description>Socket flagged a self-propagating worm in @automagik/genie, pgserve, and 14 sibling Namastex Labs packages. It steals 40 credential categories and republishes itself.</description><pubDate>Tue, 28 Apr 2026 16:30:00 GMT</pubDate><category>security</category><category>npm</category><category>supply-chain</category><category>canisterworm</category><category>security</category><category>namastex</category><category>teampcp</category><category>pypi</category><category>credential-theft</category><author>luca-reinhardt</author></item><item><title>A malicious GGUF file owns your SGLang server: CVE-2026-5760 is an unpatched 9.8</title><link>https://devtake.dev/article/sglang-cve-2026-5760-gguf-rce/</link><guid isPermaLink="true">https://devtake.dev/article/sglang-cve-2026-5760-gguf-rce/</guid><description>SGLang&apos;s reranker renders chat templates without a sandbox. Load a hostile GGUF, hit /v1/rerank, and the attacker has Python on your inference box. No patch yet.</description><pubDate>Mon, 27 Apr 2026 11:30:00 GMT</pubDate><category>security</category><category>sglang</category><category>cve-2026-5760</category><category>supply-chain</category><category>ai-security</category><category>llm</category><category>rce</category><category>jinja2</category><category>gguf</category><author>luca-reinhardt</author></item><item><title>A Discord group guessed Anthropic&apos;s URL pattern and walked into Claude Mythos</title><link>https://devtake.dev/article/anthropic-mythos-breach-discord/</link><guid isPermaLink="true">https://devtake.dev/article/anthropic-mythos-breach-discord/</guid><description>Bloomberg reports a small group accessed Anthropic&apos;s locked-down Mythos model the same day it launched, using credentials from a third-party contractor and educated URL guessing.</description><pubDate>Sat, 25 Apr 2026 11:00:00 GMT</pubDate><category>ai</category><category>anthropic</category><category>claude-mythos</category><category>ai-security</category><category>supply-chain</category><category>project-glasswing</category><category>mercor</category><category>security</category><author>dieter-morelli</author></item><item><title>Malicious npm and PyPI packages turn dev servers into Chinese LLM proxies</title><link>https://devtake.dev/article/gpt-proxy-npm-supply-chain/</link><guid isPermaLink="true">https://devtake.dev/article/gpt-proxy-npm-supply-chain/</guid><description>Aikido found a stage-2 Go binary inside two health-check-themed packages that runs an OpenAI-compatible router routing Claude, GPT, and Gemini traffic through Chinese aggregators.</description><pubDate>Sat, 25 Apr 2026 07:30:00 GMT</pubDate><category>security</category><category>supply-chain</category><category>npm</category><category>pypi</category><category>ai-security</category><category>malware</category><category>llm</category><category>china</category><category>credential-theft</category><author>luca-reinhardt</author></item><item><title>Bitwarden CLI got backdoored for 90 minutes. The worm calls itself &apos;Shai-Hulud: The Third Coming.&apos;</title><link>https://devtake.dev/article/bitwarden-cli-shai-hulud-npm-worm/</link><guid isPermaLink="true">https://devtake.dev/article/bitwarden-cli-shai-hulud-npm-worm/</guid><description>A malicious @bitwarden/cli@2026.4.0 hit npm on April 22. The payload steals npm tokens, cloud secrets, and Claude Code credentials, then self-replicates.</description><pubDate>Thu, 23 Apr 2026 19:00:00 GMT</pubDate><category>security</category><category>bitwarden</category><category>shai-hulud</category><category>npm</category><category>supply-chain</category><category>worm</category><category>credential-theft</category><category>checkmarx</category><category>cicd</category><author>luca-reinhardt</author></item><item><title>Microsoft rushed an out-of-band ASP.NET Core patch. If you shipped between April 14 and April 21, you need to rebuild.</title><link>https://devtake.dev/article/microsoft-aspnet-emergency-patch/</link><guid isPermaLink="true">https://devtake.dev/article/microsoft-aspnet-emergency-patch/</guid><description>CVE-2026-40372 lets attackers forge auth cookies on .NET 10.0.6 apps on Linux and macOS. The fix is 10.0.7. Here&apos;s what broke, who&apos;s exposed, and how to patch.</description><pubDate>Thu, 23 Apr 2026 09:30:00 GMT</pubDate><category>security</category><category>microsoft</category><category>aspnet</category><category>dotnet</category><category>cve-2026-40372</category><category>data-protection</category><category>out-of-band-patch</category><category>supply-chain</category><author>luca-reinhardt</author></item><item><title>protobuf.js RCE: a 52M/week npm package was one bad type name from code execution</title><link>https://devtake.dev/article/protobuf-javascript-rce-cve/</link><guid isPermaLink="true">https://devtake.dev/article/protobuf-javascript-rce-cve/</guid><description>GHSA-xq3m-2v4x-88gg hits protobuf.js ≤8.0.0 / ≤7.5.4. Attacker-controlled schemas executed arbitrary JS on decode. One-line fix patched it.</description><pubDate>Tue, 21 Apr 2026 12:00:00 GMT</pubDate><category>security</category><category>npm</category><category>protobuf</category><category>javascript</category><category>supply-chain</category><category>rce</category><category>endor-labs</category><category>grpc</category><author>luca-reinhardt</author></item><item><title>Inside GitHub&apos;s fake star economy: 6 million bought stars and how to spot them</title><link>https://devtake.dev/article/github-fake-star-economy/</link><guid isPermaLink="true">https://devtake.dev/article/github-fake-star-economy/</guid><description>A Carnegie Mellon study counted 6 million suspected fake stars across 18,617 GitHub repos. Here&apos;s what the StarScout research actually found and how to read a star count now.</description><pubDate>Mon, 20 Apr 2026 16:00:00 GMT</pubDate><category>open-source</category><category>github</category><category>fake-stars</category><category>starscout</category><category>open-source</category><category>software-research</category><category>icse-2026</category><category>supply-chain</category><category>ai-repos</category><author>soren-vanek</author></item><item><title>Vercel got breached through a third-party AI tool&apos;s OAuth app. Here&apos;s what leaked.</title><link>https://devtake.dev/article/vercel-breach-april-2026/</link><guid isPermaLink="true">https://devtake.dev/article/vercel-breach-april-2026/</guid><description>A Context.ai compromise let attackers take over a Vercel employee&apos;s Google Workspace. Non-sensitive env vars were exposed, and a ShinyHunters persona is asking $2M.</description><pubDate>Mon, 20 Apr 2026 09:00:00 GMT</pubDate><category>security</category><category>vercel</category><category>data-breach</category><category>oauth</category><category>supply-chain</category><category>context-ai</category><category>shinyhunters</category><category>google-workspace</category><author>luca-reinhardt</author></item><item><title>Trivy got hijacked: 75 of 76 version tags rewrote to drop a CI secret-stealer</title><link>https://devtake.dev/article/trivy-supply-chain-attack-compromise/</link><guid isPermaLink="true">https://devtake.dev/article/trivy-supply-chain-attack-compromise/</guid><description>Attackers force-pushed 75 of 76 trivy-action tags to a malicious commit. Pinning by tag turned a trusted scanner into an infostealer for CI pipelines.</description><pubDate>Sat, 18 Apr 2026 08:30:00 GMT</pubDate><category>security</category><category>supply-chain</category><category>trivy</category><category>aqua-security</category><category>github-actions</category><category>cicd</category><category>devsecops</category><category>teampcp</category><author>luca-reinhardt</author></item></channel></rss>