1.
2.
GitHub, PyPI add time-based defenses against supply chain attacks
(bleepingcomputer.com)
3.
GitHub, PyPI add time-absed defenses against supply chain attacks
(bleepingcomputer.com)
4.
LLM Usage in Debian: Three Proposals
(news.ycombinator.com)
5.
The Fedora 45 Sausage Factory
(news.ycombinator.com)
6.
7.
8.
Moonstone: Modern, cross-platform Lua runtime and package manager written in Zig
(news.ycombinator.com)
9.
Hackers backdoor Jscrambler npm package with infostealer malware
(bleepingcomputer.com)
10.
11.
Injective SDK on npm infected with cryptocurrency wallet stealer
(bleepingcomputer.com)
12.
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
(bleepingcomputer.com)
13.
14.
Dependencies should be fetched directly from VCS
(news.ycombinator.com)
15.
Show HN: Meow – The 4th and final JavaScript runtime and toolchain
(news.ycombinator.com)
16.
Show HN: CLI that helps AI agents avoid vulnerable dependencies
(news.ycombinator.com)
17.
18.
Google Wallet just got an update to track your online orders
(androidauthority.com)
19.
Too many R packages: CRAN is inundated with submissions
(news.ycombinator.com)
20.
21.
Swift Package Index joins Apple
(news.ycombinator.com)
22.
Swift Package Index Joins Apple
(news.ycombinator.com)
23.
Show HN: Treedocs: Documentation that automatically checks for staleness
(news.ycombinator.com)
24.
Microsoft says Windows 11 26H2 is coming soon, details upgrade process
(bleepingcomputer.com)
25.
Microsoft links Mastra AI supply chain attack to North Korean hackers
(bleepingcomputer.com)
26.
AURpocalypse now: a look at the recent AUR attacks
(news.ycombinator.com)
28.
Apple Foundation Models
(news.ycombinator.com)
29.
Show HN: Kage – Shadow any website to a single binary for offline viewing
(news.ycombinator.com)
30.