15 related articles

A fake critical SQLite CVE fabricated by AI hallucination passed official review, exposing weaknesses in vulnerability disclosure. Analysis of impacts and governance strategies.

Analysis of an LLM-assisted security audit that found 41 vulnerabilities in GlobaLeaks for just $3,140, exploring AI security auditing's cost-effectiveness, methodology, and impact on open-source security.

GitHub Sponsors has cumulatively funded open source maintainers over $100M, marking a shift from passion-driven to sustainable development. Explore what this milestone means for open source.

Anthropic launches Project Glass Wing—its Mythos Preview model found over 10,000 critical infrastructure vulnerabilities in hours, spanning 150 organizations across 15 countries. A deep dive into AI security auditing.

OpenInspect's Multi-Repo Automations lets AI coding agents maintain up to 10 repositories on a schedule simultaneously — isolated sessions, independent PRs, and fault-tolerant execution for security sweeps, dependency upgrades, and framework migrations.

Governments frequently label open source software as critical infrastructure, but the real test is whether budgets flow to maintainer time, infrastructure, and incident response—not just surface-level audit reports.

The new U.S. Executive Order requires government software suppliers to provide verifiable security assurances and mandates the SBOM system. This article analyzes the policy's core demands, real impact on suppliers, and the chain of challenges.

AI coding assistants (Copilot/Cursor/Claude Code) frequently introduce vulnerable dependencies and hallucinate package names. This post analyzes an Agent-native CLI security tool and the shift-left security philosophy for AI-era supply chains.

GitHub Advisory Database hits historic vulnerability submission records, reflecting systemic security pressure on open-source supply chains. A deep analysis of driving factors, response strategies, and practical recommendations.
How GitHub Manages Open Source Depende…
GitHub's OSPO uses automated dependency scanning, policy enforcement, and transitive risk detection to embed open source license compliance into CI/CD pipelines at scale.
6 Free GitHub Security Settings Every …
GitHub offers 6 free security settings for open source maintainers: 2FA, Dependabot alerts, secret scanning, branch protection, permission reviews, and code scanning. Configure once, benefit long-term.

OpenAI launches an open source vulnerability detection initiative using LLM technology to help the open source community find and fix software vulnerabilities, competing with Google and Microsoft in AI security.
Product ReviewsDeep dive into Claude Code 2.0's core features: checkpoint rollback, context window visualization, usage tracking, native VS Code extension, and MCP server integration, with comparisons to Cursor and Codex.
Tech FrontiersSynopsys Unified GitHub Action releases v6.0.0 with SAST and SCA security scanning. Key upgrade notes, compatibility considerations, and DevSecOps best practices for smooth migration.
Tech FrontiersProject Glasswing is a collaborative AI cybersecurity initiative that discovered over 10,000 high-severity vulnerabilities in its first month, reshaping proactive security auditing at scale.