RSRushabh Shahindepwarden.hashnode.dev·3d ago · 8 min readCVSS, EPSS and KEV: how to actually prioritize dependency vulnerabilitiesEvery week a dependency scanner finds dozens of vulnerabilities. Every week most developers ignore them, because there's no time to fix 200 issues and no obvious way to know which 3 actually matter. T01I
RSRushabh Shahindepwarden.hashnode.dev·6d ago · 8 min readWhat is a Software Bill of Materials (SBOM) and why your team needs oneWhen a critical vulnerability like Log4Shell drops at 11pm on a Friday, the first question every security team asks is: "which of our products use Log4j?" Without an SBOM, answering that question mean00
RSRushabh Shahindepwarden.hashnode.dev·Sep 19 · 3 min readTransitive dependencies explained: why a package you never installed can still break your buildYou run a scan and get a HIGH severity finding in minimist@1.2.0. You grep your package.json — it isn't there. So why is it in your build? Direct vs transitive A direct dependency is one you declared 00
RSRushabh Shahindepwarden.hashnode.dev·Sep 10 · 7 min readWe checked every single-typo of the 30 most popular npm and PyPI packages. Here's what's actually registered.Typosquatting is one of the best-documented supply-chain attack techniques — publish a package one keystroke away from something popular, wait for developers to fat-finger npm install, and you have a 00
RSRushabh Shahindepwarden.hashnode.dev·Sep 10 · 5 min readSAST vs SCA: why your CI pipeline needs bothWhen security teams talk about "scanning" code in CI/CD, they usually mean one of two very different things: scanning the code you wrote (SAST) or scanning the open-source code you imported (SCA). Bot00