Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0
Doug White talks about manually vetting software downloads from GitHub, NPM, and PyPI before allowing them onto a normal machine.
That process included sandboxing the code in a Linux VM, reviewing it manually, and even using multiple AI models to inspect the files before installation.
The clip highlights a growing supply-chain security problem inside open-source ecosystems.
Developers increasingly worry that packages, updates, or dependencies could contain malware, hidden payloads, or compromised code paths — forcing users to treat even routine downloads with suspicion.
Are software repositories becoming too risky to trust by default, or is this simply the new normal for secure development?
Subscribe to our podcasts: https://securityweekly.com/subscribe
#OpenSource #SupplyChainSecurity #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec
SOCIAL SHARE CARD GENERATOR