#
DIFF.BLOG
New
Following
Discover
Jobs
More
Top Writers
Suggest a blog
Upvotes plugin
Report bug
Contact
About
Sign up
The home for great developer writing.
We surface the best developer writing from thousands of independent blogs, updated daily.
Join Diff.blog
TOPICS
A Retrospective Survey of 2024/2025 Open Source Supply Chain Compromises
129
·
Filippo Valsorda
·
Oct. 10, 2025, 4 p.m.
Open Source
supply chain security
Phishing
GitHub Actions
Summary
The blog post discusses common root causes of open source supply chain compromises that can be mitigated, specifically focusing on phishing, control handoff, and unsafe GitHub Actions triggers.
Read full post on words.filippo.io →
MORE POSTS LIKE THIS
Self Download vs. Certified Crates?
Users Rust Lang ·
Jun 10, 2026
Rust Programming
dependency management
Open Source Activity in 2025
Andrew Nesbitt ·
Dec 31, 2025
Open Source
github
zizmor
Thiago Perrotta ·
Oct 3, 2025
static-analysis
GitHub Actions
What's missing to have reproducible builds on PyPI
brettcannon ·
Aug 16, 2026
Python
packaging
Twenty Years of my Open Source Project
Nemanja Trifunovic ·
Aug 13, 2026
Open Source
C++
Awesome made by Brazilians
Notes Ghed ·
Aug 13, 2026
English
Cool links
Discover more posts →
AUTHOR
BLOG POST FEATURED ON
Hacker News
13 points
r/CryptoAnarchy
1 points
Add this plugin to your blog
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub
Continue with Google