As someone deep into MCP (hello, I am one of the Core Maintainers of the protocol), what Kelsey alludes to here is π―
MCP completely removes the need to care about underlying API shape. Intent is what matters in a universal adapter. Behind the scenes you can use SOAP/XML for all we care.
12.02.2026 21:23
π 59
π 7
π¬ 6
π 0
Safer Docker Hub Pulls via a Sonatype-Protected Proxy | Docker
Learn from Docker experts to simplify and advance your app development and management with Docker. Stay up to date on Docker events and new version
Running Docker Hub pulls at scale?
This post shows how to add a Sonatype-protected proxy to centralize policy checks, cache trusted images, and keep existing workflows intact.
Learn how β https://bit.ly/4jQBm2g
23.01.2026 14:00
π 1
π 1
π¬ 0
π 0
Framing bans as existential while treating sexual abuse as a regulatory detail is the real slippery slope. Why the digital exceptionalism - this would never be accepted in printed material. The harm was foreseeable, the safeguards were obvious, and limited action only came under pressure.
15.01.2026 07:42
π 17
π 0
π¬ 0
π 1
Comics peeps. I am finally clocking off from work tomorrow and doing my annual splurge on as many of the year's best titles as I can get my hands on. What've been your highlights of 2025? Ongoing weeklies, collected tpbs, one-off graphic novels, reissues, indies, whatever you've got.
18.12.2025 16:13
π 31
π 18
π¬ 22
π 0
Blog - Socket
Learn about the latest security news, Socket updates and announcements.
Also in no particular order blogs that will keep you up-to-date with the latest supply chain attacks
socket.dev/blog
09.12.2025 11:22
π 0
π 0
π¬ 1
π 0
Version 1 of the OWASP AI testing guide just got published.
I promise you, from my own experience, this will save you a lot of heartache.
github.com/OWASP/www-pr...
27.11.2025 10:31
π 42
π 14
π¬ 0
π 1
GitHub - lirantal/npm-security-best-practices: Collection of npm package manager Security Best Practices
Collection of npm package manager Security Best Practices - lirantal/npm-security-best-practices
Given Shai-Hulud comeback (hello SHA1-HULUD π)
It is quite timely to share my up-to-date repository for modern npm security best practices against supply chain malware attacks:
27.11.2025 07:01
π 9
π 4
π¬ 2
π 0
Shai-Hulud Returns: Over 300 NPM packages infected via fake Bun runtime within hours
helixguard.ai/blog/malicio...
24.11.2025 12:38
π 11
π 2
π¬ 1
π 1
Troy Parrott's 96th-minute winner keeps Ireland's World Cup hopes alive!
The 23-year-old's hat-trick earns his country victory and a spot in the play-offs, breaking Hungarian hearts in the process.
Remarkable scenes in Budapest.
16.11.2025 16:08
π 167
π 21
π¬ 0
π 14
Towards a secure by default GitHub Actions Β· community Β· Discussion #179107
Why are you starting this discussion? Product Feedback What GitHub Actions topic or product is this about? Workflow Configuration Discussion Details Today, GitHub announced upcoming changes to the ...
π GitHub is making Actions more secure by default
We recently announced upcoming changes to the pull_request_target event and environment protection rules to make GitHub Actions more secure by default.
Weβve opened a discussion to gather feedback π
π github.com/orgs/communi...
11.11.2025 18:38
π 6
π 4
π¬ 0
π 0
Introduction - OWASP Top 10:2025 RC1
OWASP Top 10:2025 RC1
The release candidate of the OWASP Top 10 2025 has been released
owasp.org/Top10/2025/0...
The definitive release should be out on November 20th
07.11.2025 12:19
π 8
π 11
π¬ 0
π 0
There's some really big caveats to this. A thread.
05.11.2025 15:52
π 157
π 74
π¬ 6
π 2
Security-Focused Prompts | Vibe Coding Framework
Just prompt it they way you like. E.g with something like this: docs.vibe-coding-framework.com/document-tem...
01.11.2025 08:59
π 4
π 1
π¬ 1
π 1
π¨ Open source supply chain attacks are exploding.
Starting today, that ends.
Weβre releasing Socket Firewall β FREE, zero-config, CLI that blocks malware before it lands on your laptop or CI.
Just run:
npm i -g sfw
sfw npm install lodash
Works for: npm, yarn, pnpm, pip, uv, and cargo.
30.09.2025 18:06
π 45
π 12
π¬ 7
π 3
The press release is here: www.secretservice.gov/newsroom/rel...
Some images are below:
23.09.2025 11:59
π 14
π 5
π¬ 2
π 3
Ongoing Supply Chain Attack Targets CrowdStrike npm Packages...
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Halud" supply chain attack that previously hit Tinycolor and dozen...
π¨ Update: The "Shai-Hulud" supply chain attack has expanded to nearly 500 trojanized npm packages, including several from CrowdStrike, all using the same malware first seen in Tinycolor.
Full details and package list: socket.dev/blog/ongoing... #NodeJS #JavaScript
16.09.2025 18:15
π 31
π 15
π¬ 1
π 5
Hi everyone. The 'next day' busy-ness has fully set in.
Since I still haven't gotten any followup from npm regarding account actions taken, and given that I have now been approached by authorities, I will need to hold off on the post-mortem for a day or two.
Sincerest apologies for the delay.
09.09.2025 14:10
π 29
π 3
π¬ 3
π 0
π¨URGENT: A series of popular packages maintained by qix have just been compromised.
Compromised packages include:
β’ has-ansi - 12 million weekly downloads - V6.0.1
β’ supports-hyperlinks - 19m weekly downloads - v4.1.1
β’ chalk-template - 3.9m weekly downlaods - V1.1.1
08.09.2025 15:45
π 5
π 4
π¬ 1
π 1
A cryptostealer malware was pushed to a number of npm packages including debug, chalk , and a number of utility packages as a result of the compromise of a single contributor.
We published guidance for customers and non-customers for how to detect if you were affected:
semgrep.dev/blog/2025/ch...
08.09.2025 17:21
π 0
π 1
π¬ 0
π 0