Mendral

Blog

Product

Supply Chain Attacks Don't Wait for CVEs

By the time a CVE exists, the bad version is already in thousands of CI pipelines. Here's the last year of npm and Actions attacks, why scanners are reactive by design, and the supply chain agent we shipped to catch dependency changes at the PR.

Sam Alba