Verifiedapp Blog
Home All posts

Tag

#supply-chain

Security Headers

Subresource Integrity (SRI): trusting the CDN you do not control

When you load a script from a CDN, you are trusting that server to send the exact file you expect. Subresource Integrity makes the browser verify it instead of taking it on faith.

Sep 7, 2026 · 3 min read
Supply Chain

Shai-Hulud: the first self-propagating npm worm (2025), explained

Most supply-chain incidents are a single bad package. Shai-Hulud was different: it used what it stole to publish itself into more packages, on its own.

Aug 3, 2026 · 3 min read
Supply Chain

The 3 npm settings that stop most supply-chain attacks (lockfile, npm ci, cooldown)

Most dependency supply-chain risk is blunted by three boring npm settings. They are not glamorous, but they remove the easy ways a bad package slips in.

Jun 29, 2026 · 3 min read
Supply Chain

The npm supply-chain attacks every shipper should know in 2026

Your app ships dozens of packages you never chose. When one gets hijacked, you ship the attack too. Here is the pattern, the big recent incidents, and the defenses.

May 21, 2026 · 3 min read
© VerifiedApp — automated security scanning & trust badges. RSS