When security teams scan their container environments for the first time, they often discover hundreds of known vulnerabilities, and almost none of them trace back to application code. The overwhelming majority come from packages that shipped with the base image: shells, compilers, debug utilities, and libraries the application never calls. In a software supply chain...
<p>The Dev channel has been updated to 151.0.7872.0 for Windows, Mac and Linux.</p><p>A partial list of changes is available in the <a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7865.2..151.0.7872.0?pretty=fuller&n=10000">Git log</a>. Interested in <a href="https://www.chromium.org/getting-involved/dev-channel/">switching</a> release channels? Find out <a href="https://www.chromium.org/getting-involved/dev-channel/">how</a>. If you find a new issue, please let us know by <a href="https://crbug.com/">filing a bug</a>. The <a href="https://productforums.google.com/forum/#!forum/chrome">community help forum</a> is also a great place to reach out for help or learn about common issues.</p><p>Chrome Release Team<br /><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>
<p>Hi everyone! We've just released Chrome Dev 151 (151.0.7872.3) for Android. It's now available on <a href="https://play.google.com/store/apps/details?id=com.chrome.dev">Google Play</a>.</p><p>You can see a partial list of the changes in the <a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7863.2..151.0.7872.3?pretty=fuller&n=10000">Git log</a>. For details on new features, check out the <a href="https://blog.chromium.org">Chromium blog</a>, and for details on web platform updates, check <a href="https://www.chromestatus.com/features#milestone%3D151">here</a>.</p><p>If you find a new issue, please let us know by <a href="https://code.google.com/p/chromium/issues/entry?template=Android%20Issue">filing a bug</a>.</p><p>Chrome Release Team<br /><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>
VoidZero, the team behind Vite, Vitest, Rolldown, Oxc, and Vite+, is joining Cloudflare. Vite stays open source, vendor-agnostic, and built for everyone.
Learn how Endava is using AI agents, ChatGPT Enterprise, and Codex to accelerate software delivery, automate workflows, and build an AI-native culture across the enterprise.
Part one The last twelve months have been rough on the open source supply chain. Axios was compromised on npm and shipped a remote access trojan inside otherwise normal-looking releases. LiteLLM’s PyPI package was hijacked to...
Most days in her chambers, Judge Maritza Braswell, a federal magistrate judge in Colorado, sifts through stacks of documents written by people without a lawyer. Many of them can’t afford to hire a lawyer, and others have cases too weak or too small to interest one. She reads each one carefully, mindful of how daunting…
An interview with Microsoft CEO Satya Nadella about figuring out Microsoft's role in AI, the relationship with OpenAI, Capex, Software, and a potential new agentic platform.
<p> Generate and edit images with precise scene control </p> <p> <a href="https://www.producthunt.com/products/mai-image-2-5?utm_campaign=producthunt-atom-posts-feed&utm_medium=rss-feed&utm_source=producthunt-atom-posts-feed">Discussion</a> | <a href="https://www.producthunt.com/r/p/1162954?app_id=339">Link</a> </p>
A new npm worm is abusing binding.gyp to trigger node-gyp during install, letting malicious packages run code without lifecycle scripts. It steals credentials, persists in GitHub, and self-propagates across maintainers.
Secure-by-design types can turn common bugs into compile-time errors. This post explores how type-level security could help prevent entire classes of AI-generated vulnerabilities.
An AI security budget should fund more than visibility. The real priority is unified governance and enforcement across agentic development and production apps.