All posts

June 4, 2026

What Dependabot Misses: 6 npm Supply-Chain Attacks That Got Through

Dependabot flags known CVEs. None of these six attacks had a CVE when they hit production.

dependabotnpmsupply-chainmalware

Catch the next supply-chain attack on the PR that adds it.

14-day free trial · no card required