A massive and highly coordinated supply chain assault is currently ripping through the JavaScript developer ecosystem. Security...
GitHub Actions
In a critical security alert for the PHP community, Nils Adermann, Co-Creator of Composer, has issued an...
The software supply chain has just weathered another high-impact assault. The Socket Threat Research team has uncovered...
A critical update has been issued for Gemini CLI (@google/gemini-cli) and the run-gemini-cli GitHub Action to address...
The password management world was rocked this week as researchers from Socket revealed a major supply chain...
The cybersecurity world is facing a sprawling supply chain compromise as official distribution channels for Checkmarx, a...
Today, security firm Checkmarx has identified a recent supply chain security incident. The breach involved the publication...
In a sophisticated supply chain manipulation, the xygeni-action GitHub Action was recently targeted by a critical “tag...
Christopher Robinson, Chief Technology Officer and Chief Security Architect at the Open Source Security Foundation (OpenSSF), has...
Recently, the code hosting platform GitHub published a blog post announcing that, starting March 1, 2026, GitHub...
Microsoft-owned code hosting platform GitHub has announced a new pricing change for its Actions service. Previously, GitHub...
A critical vulnerability—CVE-2025-54594 (CVSS 9.1)—has been identified in the React Native Bottom Tabs project, exposing the repository...
A critical command injection vulnerability has been disclosed in the widely used GitHub Action tj-actions/branch-names, affecting over...