Security 9
- github's agent audit api is the boring feature that matters
- Watch out - that recruiter profile might be a scam. Check here first.
- How to safely inspect a repository before running anything on your machine
- Watch out, your recruiter might be a scam
- From capital one to unreviewed AI code the same ssrf, different decade
- Workload Identity Is Becoming the Real Cloud Control Plane
- nodes/proxy Was Never a Monitoring Permission
- User Namespaces Are a Bigger Container Milestone Than Most Docker Headlines
- The LiteLLM Supply Chain Attack — What AI-Dependent Codebases Should Audit