Discussion
Loading...

#Tag

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
jbz boosted
jbz
@jbz@indieweb.social  ·  activity timestamp 3 days ago

headache Shai-Hulud Returns: Over 300 NPM Packages and 27K+ Github Repos infected via Fake Bun Runtime Within Hours // HelixGuard

https://helixguard.ai/blog/malicious-sha1hulud-2025-11-24

#shaihulud #npm #supplychain #infosec #github

HelixGuard

Supply chain security, vulnerability intelligence, and malware detection.
  • Copy link
  • Flag this post
  • Block
jbz
@jbz@indieweb.social  ·  activity timestamp 3 days ago

headache Shai-Hulud Returns: Over 300 NPM Packages and 27K+ Github Repos infected via Fake Bun Runtime Within Hours // HelixGuard

https://helixguard.ai/blog/malicious-sha1hulud-2025-11-24

#shaihulud #npm #supplychain #infosec #github

HelixGuard

Supply chain security, vulnerability intelligence, and malware detection.
  • Copy link
  • Flag this post
  • Block
jbz
@jbz@indieweb.social  ·  activity timestamp 2 weeks ago

「 given the current situation, QLC NAND is expected to overtake TLC in popularity by early 2027, marking a significant shift in the storage landscape. While enterprise-grade QLC SSDs would entirely power this pivot, Sandisk has already raised NAND prices by 50%, according to another DigiTimes report, after initially warning of a 10% increase two months ago 」

https://www.tomshardware.com/pc-components/hdds/ai-triggers-hard-drive-shortage-amidst-dram-squeeze-enterprise-hard-drives-on-backorder-by-2-years-as-hyperscalers-switch-to-qlc-ssds

#ai #datacenters #supplychain

  • Copy link
  • Flag this post
  • Block
Andrew Nesbitt boosted
Mike Fiedler, Code Gardener
@miketheman@hachyderm.io  ·  activity timestamp 2 weeks ago

New @pypi blog

TL, DR:
- Trusted Publishing used for 25% of all files uploaded in Oct 2025
- GitLab Self-Managed now in beta
- Pending Publishers can be added for Organizations, too!

#Python #SupplyChain #Security

Read it here: https://blog.pypi.org/posts/2025-11-10-trusted-publishers-coming-to-orgs/

  • Copy link
  • Flag this post
  • Block
Mike Fiedler, Code Gardener
@miketheman@hachyderm.io  ·  activity timestamp 2 weeks ago

New @pypi blog

TL, DR:
- Trusted Publishing used for 25% of all files uploaded in Oct 2025
- GitLab Self-Managed now in beta
- Pending Publishers can be added for Organizations, too!

#Python #SupplyChain #Security

Read it here: https://blog.pypi.org/posts/2025-11-10-trusted-publishers-coming-to-orgs/

  • Copy link
  • Flag this post
  • Block
phildini boosted
Seth Larson
@sethmlarson@mastodon.social  ·  activity timestamp 4 weeks ago

⚞NEW⚟ “Trailblazing Python Security” dedicated talk track coming for #PyConUS 🛡️ 🐍🔥 We are looking for sponsors interested in supporting security in the Python ecosystem:

https://pycon.blogspot.com/2025/10/pycon-us-2026-call-for-proposals-now.html#%3A~%3Atext%3DTrailblazing%20Python%20Security

#python #opensource #oss #security #supplychain

PyCon US 2026 - Call for Proposals Now Open!

We’re so excited to announce that PyCon US 2026 is heading to California for our first year in our sunny new host city of Long Beach, CA ! W...
  • Copy link
  • Flag this post
  • Block
Seth Larson
@sethmlarson@mastodon.social  ·  activity timestamp 4 weeks ago

⚞NEW⚟ “Trailblazing Python Security” dedicated talk track coming for #PyConUS 🛡️ 🐍🔥 We are looking for sponsors interested in supporting security in the Python ecosystem:

https://pycon.blogspot.com/2025/10/pycon-us-2026-call-for-proposals-now.html#%3A~%3Atext%3DTrailblazing%20Python%20Security

#python #opensource #oss #security #supplychain

PyCon US 2026 - Call for Proposals Now Open!

We’re so excited to announce that PyCon US 2026 is heading to California for our first year in our sunny new host city of Long Beach, CA ! W...
  • Copy link
  • Flag this post
  • Block
Yogthos
@yogthos@social.marxist.network  ·  activity timestamp 2 months ago

A short intro to systems thinking by examining how China’s digital yuan & smart logistics slash delays and improve information flow as a case study.

https://dialecticaldispatches.substack.com/p/chinas-systemic-shift

#China #DigitalCurrency #economy #SupplyChain

China's Systemic Shift

How the Digital Yuan Rewires the Global Supply Chain
  • Copy link
  • Flag this post
  • Block
The Japan Times
@thejapantimes@mastodon.social  ·  activity timestamp 2 months ago

More German companies are choosing Japan as their manufacturing hub for Asia, according to a survey by the German Chamber of Commerce and Industry in Japan. https://www.japantimes.co.jp/business/2025/09/22/companies/german-companies-japan-survey/?utm_medium=Social&utm_source=mastodon #business #companies #germany #germanjapanrelations #ahkjapan #supplychain #manufacturing #china #southeastasia

The Japan Times

German companies choosing Japan as Asia manufacturing hub: survey

The country is valued for its stability, affordability and proximity to other major markets, according to the survey by the German Chamber of Commerce and Industry in Japan.
  • Copy link
  • Flag this post
  • Block
Charly Coste 🇫🇷 boosted
Python Package Index
@pypi@fosstodon.org  ·  activity timestamp 3 months ago

PyPI now checks for expired domains to prevent domain resurrection attacks, a type of supply-chain attack where someone buys an expired domain and uses it to take over #PyPI accounts through password resets. #Python#OpenSource#SupplyChain#Security
https://blog.pypi.org/posts/2025-08-18-preventing-domain-resurrections/

  • Copy link
  • Flag this post
  • Block
Python Package Index
@pypi@fosstodon.org  ·  activity timestamp 3 months ago

PyPI now checks for expired domains to prevent domain resurrection attacks, a type of supply-chain attack where someone buys an expired domain and uses it to take over #PyPI accounts through password resets. #Python#OpenSource#SupplyChain#Security
https://blog.pypi.org/posts/2025-08-18-preventing-domain-resurrections/

  • Copy link
  • Flag this post
  • Block
Yogthos boosted
China Business Forum
@cnbusinessforum@mstdn.business  ·  activity timestamp 4 months ago

The #future of #robotics is unfolding in #Hubei, and the #world is taking notice. At the 3rd #China#International#SupplyChain#Expo (#CISCE) in #Beijing, the province cemented its role as a #powerhouse in #humanoid robotics, hosting a high-profile #matchmaking #conference that drew #global #leaders, #innovators, and #investors. https://cnbusinessforum.com/hubei-takes-center-stage-in-global-humanoid-robotics-innovation-at-cisce-2025/

  • Copy link
  • Flag this post
  • Block
China Business Forum
@cnbusinessforum@mstdn.business  ·  activity timestamp 4 months ago

The #future of #robotics is unfolding in #Hubei, and the #world is taking notice. At the 3rd #China#International#SupplyChain#Expo (#CISCE) in #Beijing, the province cemented its role as a #powerhouse in #humanoid robotics, hosting a high-profile #matchmaking #conference that drew #global #leaders, #innovators, and #investors. https://cnbusinessforum.com/hubei-takes-center-stage-in-global-humanoid-robotics-innovation-at-cisce-2025/

  • Copy link
  • Flag this post
  • Block
Nonilex
@Nonilex@masto.ai  ·  activity timestamp 9 months ago
#Trump’s #tariffs target countries that are major suppliers of a wide range of goods to the #UnitedStates.

For American families, the likely result is higher #prices nearly everywhere they turn — in grocery aisles, at car dealerships, at electronics stores & at the pump.

#economy #prices #consumers#PersonalFinance#TrumpTariffs #idiocracy#USpol #law#Canada#Mexico#China
https://www.nytimes.com/article/trump-tariffs-prices-consumers.html?smid=nytcore-ios-share&referringSource=articleShare&sgrp=p&pvid=B62F2EB0-707F-4418-8A92-3ADDA21FC8D0

Nonilex
@Nonilex@masto.ai replied  ·  activity timestamp 9 months ago

… #trading data & economic studies suggest #consumers in the #US will see higher #prices on a products from vegetables & meat to cellphones & cars. While a few companies may not pass on the cost of the #tariff, many are likely to raise prices on their products.
“Because of the combination of these 3 countries, it’s going to be difficult to go down an aisle of a grocery store & not see some sort of inflationary effect,” said Jason Miller, a prof of #SupplyChain management at Michigan State.
#Trump

  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-alpha.5 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login