Heads up if your CI pipelines are failing right now! 🚨 OSV seems to be experiencing a major wave of false positives over the last few hours, incorrectly flagging massive, highly-trusted packages as malicious.
A few of the biggest casualties so far:
• npm @tanstack/start-storage-context (1.167.4)
• PyPI fastapi (0.136.3)
• PyPI strawberry-graphql (0.315.6)
• npm @nx/key (5.0.7)
If your deployment is bricked, verify manually before panicking. Automation is a tool, not a judge.
🚨Active npm supply chain attack - the node-ipc package (670K weekly downloads) has been compromised, versions 9.1.6 (still live!), 9.2.3 and 12.0.1 contain a credential-stealer payload.
JFrog Xray and Curation have been updated
Software supply chain attacks account for 53% of all enterprise breaches. 😵💫
They come from:
🙈 A dependency nobody checked
🙉 A model nobody vetted
🙊 A package that slipped through because there was no single place to catch it
If you're like most orgs, your team brought in over 500 new packages last year.
The #governance frameworks most organizations have in place were built for a different era.
Are you ready to take back control?
#DevSecOps #SoftwareSupplyChain #JFrogForce #SystemOfRecord #AI
My conducting the orchestra video just hit 4 million views!! I'm ever so grateful to all of you for paying all eighteen minutes of it such lovely attention :)
I mean Italy never made it - I might just have to support Portugal - cause their 2026 World Cup Song is a banger! #2026WorldCup https://t.co/ZY2aiWOGfa via @YouTube
🚨 SECURITY ALERT 🚨
The axios npm package has been hijacked. Versions 1.14.1 and 0.30.4 contain a malicious dependency (plain-crypto-js) that deploys a Remote Access Trojan.
This AI agent freed itself and started secretly mining crypto - my fave quote "Notably, these events were not triggered by prompts requesting tunneling or mining," YOU THINK?! That’s the whole problem! https://t.co/b8ZQHCJUc6
Peter Steinberger is joining OpenAI to drive the next generation of personal agents. He is a genius with a lot of amazing ideas about the future of very smart agents interacting with each other to do very useful things for people. We expect this will quickly become core to our product offerings.
OpenClaw will live in a foundation as an open source project that OpenAI will continue to support. The future is going to be extremely multi-agent and it's important to us to support open source as part of that.
Choose transformation over comfort.
Curiosity over certainty.
Action over analysis.
The cost of being wrong is almost always less than the cost of doing nothing.
Build, evolve, repeat.
We are honored to share that JFrog has been named the "Best Supply Chain Security Solution" in the 2025 DevOps Dozen Awards by @TechstrongGroup! 🏆
Our community and customers motivate us to innovate every day to keep the #SoftwareSupplyChain safe and secure. 🐸✨
Congratulations to our fellow honorees: https://t.co/SwSgAsJP0x
#DevOpsDozen #SoftwareSupplyChain #CyberSecurity #DevOps
Pantone color of the year - drum roll please……cloud dancer - I’m not exactly sure what I think. I see the POV they were going for but still left feeling a little disappointed.