Supply Chain

Dependency security, trusted package ecosystems, update channel attacks, and the risks of transitive trust in software.