What Leaks Through the Pipe That Publishes
A private-to-public sync excluded every file it was supposed to exclude and still published the committer's identity, the commit bodies, and a sentence naming the directory it had just hidden.
Software composition, SBOMs, SLSA, and the third parties your risk model depends on.
15 articles
A private-to-public sync excluded every file it was supposed to exclude and still published the committer's identity, the commit bodies, and a sentence naming the directory it had just hidden.
A pre-production security review of a mobile game backend produced seven merged fixes in one day, and almost none of them added a control that was missing.
A Next.js downgrade that fixed a broken static export also put five open security advisories back into the lockfile for fifteen hours, and nothing recorded that as a decision.
Security questionnaires are not readiness plans. Third-party resilience requires joint response assumptions and tested escalation paths.
AI vendor risk does not end at demo day. Security teams need stronger procurement and contract controls before enterprise rollout.
SBOMs and provenance frameworks are useful, but only when teams connect them to real build controls and response workflows.
Third-party risk programs fail when questionnaires replace continuous validation. Here's how to operationalize risk management in today's supply-chain threat environment.
SBOMs are moving from optional artifact to expected control. Here's how to make them operationally useful instead of performative.
Log4Shell exposed what many teams already suspected: you can't defend what you can't inventory. SCA is now foundational, not optional.
Managing open source risk at enterprise scale requires process discipline, ownership, and signal-focused prioritization — not endless alert volume.
After SolarWinds, software supply chain security moved from niche concern to board-level priority. Here's a practical framework for 2021.
SolarWinds exposed a hard truth: trusted software channels can become attack channels. Here's what security leaders should do next.
Fast pipelines can quietly become high-risk pipelines. Here are the security gaps I see most often — and how to close them without slowing delivery.
'Shift left' was a good start, but it's no longer enough. Modern DevSecOps demands security controls across the entire software factory.
Most enterprises don't know what's inside the software they ship. Software Composition Analysis isn't optional anymore — here's what ignoring it actually costs.