註冊並分享邀請連結,可獲得影片播放與邀請獎勵。

Semgrep
@semgrep
Code security for builders. Catch, flag, and fix real issues before they ship, powered by security that learns as you build.
加入 May 2019
205 正在關注    4.7K 粉絲
Another npm worm: 1,485 poisoned versions, 379 packages, two intrusion paths. One via stolen tokens, another via compromised source/OIDC trusted publishing. The latter bypasses token rotation. This is the new reality: supply chain attacks exploiting *trusted* mechanisms. We've pushed out rules for Semgrep customers and listed the IoCs for those who aren't, read the blog:
顯示更多