Tag
Notes tagged “supply-chain”
Every note filed under supply-chain, newest first.
A filtered view of the notes.
2026
- Four Hundred Findings
A scanner report is not a list of your vulnerabilities. It is a list of your dependencies crossed with a database — and about one in thirty is reachable from code you actually run.
- You Don't Want Separate Repos
Repository topology decides whether coupled code shares one content-addressed snapshot or negotiates version strings across a registry boundary.