Loading…
Loading…
Tag
4 posts with this tag.
·10 min read
A self-spreading worm compromised 57 npm packages in under 2 hours using binding.gyp instead of postinstall scripts, bypassing security scanners. What it means for teams that run npm install, and the 5 controls that limit your exposure.
·9 min read
AI coding tools governance policy: which of Copilot, Cursor, or Claude Code trains on your code? DPAs, SOC 2, IP indemnification, and a use policy.
·8 min read
Copilot and Cursor send source code to vendor servers. IP risk, licensing exposure, and the org settings and policy rules engineering teams need to govern this.