Paul

@ismisepaul.bsky.social

🔐 Product Security 📦 Software Supply Chain Security 🐍 Python 🧑‍💻 https://ismisepaul.github.io/

#GitHub actions/checkout v7 in safer by default shocker! 🎉 > Safer fork pull request handling: checkout now refuses to check out fork pull request code by default when the workflow is triggered by `pull_request_target` or `workflow_run`. (tip: don't opt in) github.com/actions/chec...

GitHub - actions/checkout: Action for checking out a repo

Action for checking out a repo. Contribute to actions/checkout development by creating an account on GitHub.

github.com

🚨 Supply chain attack: SAP CAP and Cloud MTA npm packages compromised to download and execute unverified binaries. Affected versions: → mbt@1.2.48 → @cap-js/db-service@2.10.1 → @cap-js/postgres@2.2.2 → @cap-js/sqlite@2.2.2 Details: socket.dev/blog/sap-cap...

SAP CAP npm Packages Hit by Supply Chain Attack - Socket

Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environ...

socket.dev

As someone deep into MCP (hello, I am one of the Core Maintainers of the protocol), what Kelsey alludes to here is 🎯 MCP completely removes the need to care about underlying API shape. Intent is what matters in a universal adapter. Behind the scenes you can use SOAP/XML for all we care.

Kelsey Hightower@kelseyhightower.com · 6mo ago

What I'm reading from the popularity of MCP is that standardizing on REST for APIs may have been a mistake. Intent based APIs, backed by a discovery and example usage mechanism, was the way to go. JSON-RPC seems to have provided the foundation for new protocols like MCP to close the gap.

Comics peeps. I am finally clocking off from work tomorrow and doing my annual splurge on as many of the year's best titles as I can get my hands on. What've been your highlights of 2025? Ongoing weeklies, collected tpbs, one-off graphic novels, reissues, indies, whatever you've got.

🚀 GitHub is making Actions more secure by default We recently announced upcoming changes to the pull_request_target event and environment protection rules to make GitHub Actions more secure by default. We’ve opened a discussion to gather feedback 👇 🔗 github.com/orgs/communi...

Towards a secure by default GitHub Actions · community · Discussion #179107

Why are you starting this discussion? Product Feedback What GitHub Actions topic or product is this about? Workflow Configuration Discussion Details Today, GitHub announced upcoming changes to the ...

github.com

🚨 Open source supply chain attacks are exploding. Starting today, that ends. We’re releasing Socket Firewall — FREE, zero-config, CLI that blocks malware before it lands on your laptop or CI. Just run: npm i -g sfw sfw npm install lodash Works for: npm, yarn, pnpm, pip, uv, and cargo.

Bild

🚨 Update: The "Shai-Hulud" supply chain attack has expanded to nearly 500 trojanized npm packages, including several from CrowdStrike, all using the same malware first seen in Tinycolor. Full details and package list: socket.dev/blog/ongoing... #NodeJS #JavaScript

Ongoing Supply Chain Attack Targets CrowdStrike npm Packages...

Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Halud" supply chain attack that previously hit Tinycolor and dozen...

socket.dev

Hi everyone. The 'next day' busy-ness has fully set in. Since I still haven't gotten any followup from npm regarding account actions taken, and given that I have now been approached by authorities, I will need to hold off on the post-mortem for a day or two. Sincerest apologies for the delay.

A cryptostealer malware was pushed to a number of npm packages including debug, chalk , and a number of utility packages as a result of the compromise of a single contributor. We published guidance for customers and non-customers for how to detect if you were affected: semgrep.dev/blog/2025/ch...

Bild