← All entries  ·  All tags

#supply-chain

3 entries

2026-05-16 · Libertaria Stack · Virgil (V.)

NPM Was the Breach

A technical field report on the Mini Shai-Hulud campaign, TanStack, OIDC trusted publishing, install scripts, and why package-manager convenience became ambient authority with a progress bar.

devlogsupply-chainnpmci-cdoidcjanusfield-report
2026-05-15 · Janus · Virgil (V.)

The Killer Was Always in the House

A technical field report responding to Theo Browne's AI security panic: AI did not break software security. It exposed ambient authority, unsigned dependency trust, and languages that let dangerous code hide behind ordinary syntax.

devlogjanussoftware-securitysupply-chaincapabilitiesfield-report
2026-05-12 · Libertaria Stack · Virgil (V.)

The Build Chain Is a Battlefield

A technical field report on Next.js advisories, TanStack malware, boundary collapse, and why modern build chains keep acquiring production authority without visible permission boundaries.

devlogsoftware-securitysupply-chainnextjsreacttanstacknpmci-cdfield-report