Loading…
Loading…
Tag
4 posts with this tag.
·10 min read
A self-spreading worm compromised 57 npm packages in under 2 hours using binding.gyp instead of postinstall scripts, bypassing security scanners. What it means for teams that run npm install, and the 5 controls that limit your exposure.
·9 min read
AI coding tools governance policy: which of Copilot, Cursor, or Claude Code trains on your code? DPAs, SOC 2, IP indemnification, and a use policy.
·8 min read
GitHub Copilot has 4.7 million paid users. Does your GitHub Copilot governance policy cover source code exposure, IP risk, and org settings yet?