Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
livealight
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
State of the Software Supply Chain (2024)
(sonatype.com)
1 points
by
livealight
2y ago
|
0 comments
2.
▲
by
livealight
3y ago
Very neat! Did a similar project with AI generated images. Fun for days with this kind of cheap hardware!
3.
▲
by
livealight
3y ago
Thanks! It definitely passed the weekend well - do share if you end up building it!
4.
▲
Show HN: Kuvastin – An E Ink art piece that displays AI art from Google cal
(turunen.dev)
5 points
by
livealight
3y ago
|
2 comments
5.
▲
by
livealight
3y ago
It let log4j pass for as long as it was known to be good. Within hours of the CVE opening the tool was blocking it. The purpose of dependency firewalls is to avoid two things: known badly vulnerable packages AND known malicious packages tha
6.
▲
The Cyber Resilience Act Threatens the Future of Open Source
(devops.com)
4 points
by
livealight
3y ago
|
0 comments
7.
▲
by
livealight
4y ago
This exact same sentiment came through in the National Cyber Security Strategy the US released. It describes a minimum acceptable level of software development, called safe harbours, based on e.g. the NIST Secure Development Standards. Whet
8.
▲
BOM Doctor: Visualise and Patch Java SBOMS
(bomdoctor.sonatype.com)
1 points
by
livealight
4y ago
|
0 comments
9.
▲
8th State of the Software Supply Chain Report
(sonatype.com)
1 points
by
livealight
4y ago
|
0 comments
10.
▲
Check your gems: RubyGems fixes unauthorized package takeover bug
(bleepingcomputer.com)
2 points
by
livealight
4y ago
|
0 comments
11.
▲
PyPI, NuGet, NPM Flooded with Roblox and Fortnite Spam: Why?
(blog.sonatype.com)
2 points
by
livealight
5y ago
|
0 comments
12.
▲
Log4shell by the numbers- Why did CVE-2021-44228 set the Internet on Fire?
(blog.sonatype.com)
1 points
by
livealight
5y ago
|
0 comments
13.
▲
by
livealight
5y ago
Nexus Lifecycle / Nexus Auditor tends to be useful for this - in absence of a package.json it crawls the raw js files and finds their source. It can help figure out things like embedded jqueries etc. That being said, it has the same li
14.
▲
by
livealight
5y ago
insert obligatory node_modules joke here
15.
▲
by
livealight
5y ago
Yeah oddly the outcome of MTTU is a maintained transitive tree seems to be a better indicator of security status than any other more complex framework. How to do it effectively is a matter on to itself
16.
▲
State of the Software Supply Chain 2021
(sonatype.com)
15 points
by
livealight
5y ago
|
13 comments
17.
▲
by
livealight
5y ago
Lift works well - http://lift.sonatype.com
18.
▲
by
livealight
5y ago
seems to work now
19.
▲
Improving Open-Source Software Security for Java Developers
(hackernoon.com)
1 points
by
livealight
5y ago
|
0 comments