<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Supply-Chain-Security on CuraDevOps</title><link>https://curadevops.metacog.co.kr/tags/supply-chain-security/</link><description>Recent content in Supply-Chain-Security on CuraDevOps</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 19 Aug 2026 11:17:39 +0000</lastBuildDate><atom:link href="https://curadevops.metacog.co.kr/tags/supply-chain-security/index.xml" rel="self" type="application/rss+xml"/><item><title>Docker: AI coding agents can execute attacker code via pre-approved commands</title><link>https://curadevops.metacog.co.kr/insights/2026-08-19-coding-agent-horror-stories-the-command-you-already-approved/</link><pubDate>Wed, 19 Aug 2026 11:17:39 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-19-coding-agent-horror-stories-the-command-you-already-approved/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>CI/CD — Learn:&lt;/strong> Illustrates a prompt-injection attack vector where malicious repo content hijacks an AI agent&amp;rsquo;s pre-approved command scope; informs how to think about sandboxing agent-assisted pipeline steps, but no deadline or active exploit anchor.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Useful framing for setting policy on where and how AI coding agents are permitted to run in the development workflow, particularly around isolation boundaries — but no decision is forced today.&lt;/li>
&lt;/ul></description></item><item><title>Docker: AI coding agents risk exposing secrets in supply chain attacks</title><link>https://curadevops.metacog.co.kr/insights/2026-07-29-coding-agent-horror-stories-the-29-million-secret-problem/</link><pubDate>Wed, 29 Jul 2026 12:56:53 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-07-29-coding-agent-horror-stories-the-29-million-secret-problem/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>CI/CD — Learn:&lt;/strong> Vendor-authored post highlighting how AI coding agents can leak credentials into build/deploy contexts; worth evaluating your secret isolation controls if agents touch pipelines, but no concrete deadline or confirmed compromise here.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Surfaces a real risk category—AI agent access to secrets in the software supply chain—worth factoring into your AI tooling policy and golden-path standards, though this is Docker marketing with no specific incident or actionable deadline.&lt;/li>
&lt;/ul></description></item><item><title>npm adds publish-time malware scanning and dual-use metadata requirement</title><link>https://curadevops.metacog.co.kr/insights/2026-07-29-npm-publish-time-malware-scanning-and-dual-use-metadata/</link><pubDate>Wed, 29 Jul 2026 12:56:53 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-07-29-npm-publish-time-malware-scanning-and-dual-use-metadata/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>CI/CD — Plan:&lt;/strong> Teams that publish npm packages via their release pipelines should review the new dual-use metadata requirement to ensure compliance before enforcement begins; no hard deadline surfaced in the item, so schedule this in the next pipeline audit cycle.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> npm&amp;rsquo;s automated publish-time scanning strengthens the ecosystem&amp;rsquo;s supply-chain posture; worth noting as a positive signal when reviewing org-wide software supply-chain policy, but no leadership decision is required now.&lt;/li>
&lt;/ul></description></item><item><title>GitLab Dependency Scanning Auto-Remediation now in beta</title><link>https://curadevops.metacog.co.kr/insights/2026-07-17-when-a-version-bump-breaks-your-build-gitlab-fixes-it/</link><pubDate>Fri, 17 Jul 2026 12:03:24 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-07-17-when-a-version-bump-breaks-your-build-gitlab-fixes-it/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>CI/CD — Learn:&lt;/strong> Beta feature that auto-opens MRs to patch vulnerable dependencies and iterates until the pipeline passes — worth evaluating once GA, but pre-GA status caps this at Learn for now.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Beta capability targeting the OWASP dependency backlog and compliance remediation windows (PCI-DSS/FedRAMP 30-day deadlines); monitor for GA before considering for the golden path.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> breaking-change flagged&lt;/li>
&lt;/ul></description></item><item><title>GitHub Secret Scanning Custom Patterns Now Manageable via REST API</title><link>https://curadevops.metacog.co.kr/insights/2026-07-15-manage-secret-scanning-custom-patterns-via-rest-api/</link><pubDate>Wed, 15 Jul 2026 12:10:55 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-07-15-manage-secret-scanning-custom-patterns-via-rest-api/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>CI/CD — Plan:&lt;/strong> New GA endpoints let teams manage secret scanning custom patterns as code, enabling IaC-style enforcement of scanning policies across repos; schedule adoption as part of supply-chain hardening this quarter.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> GA announcement&lt;/li>
&lt;/ul></description></item></channel></rss>