注册并分享邀请链接,可获得视频播放与邀请奖励。

Semgrep
@semgrep
Code security for builders. Catch, flag, and fix real issues before they ship, powered by security that learns as you build.
加入 May 2019
205 正在关注    4.7K 粉丝
Another npm worm: 1,485 poisoned versions, 379 packages, two intrusion paths. One via stolen tokens, another via compromised source/OIDC trusted publishing. The latter bypasses token rotation. This is the new reality: supply chain attacks exploiting *trusted* mechanisms. We've pushed out rules for Semgrep customers and listed the IoCs for those who aren't, read the blog:
显示更多