u/Empzyotonal_Turn3555

How are teams protecting their software supply chain without adding more scanner noise?

Supply chain security is having its moment and every vendor has a pitch, but most of what we've tried just adds another feed of alerts on top of the ones we already ignore. dependency confusion and malicious packages are the obvious risks, but build pipeline tampering is just as real and a lot harder to catch, and the tooling landscape hasn't caught up to prioritizing any of it well.

What's worked for teams here in terms of cutting signal from noise rather than just adding another layer of detection?

reddit.com
u/Empzyotonal_Turn3555 — 3 days ago