The industry keeps face-planting on supply chain security — and it’s not because the problems are new.
We broke down the systemic issues in our new blog, "Package managers - malware delivery as a service":
https://distrust.co/blog/package-managers.html
#SupplyChainSecurity #InfoSec #DevSecOps #OpenSourceSecurity #CVE #FediSec