Software Supply Chain Attacks, Explained for Engineering Teams
Tyrell Banks on software supply chain attacks: what actually matters for engineering teams making this call.
All categories
More categories
Featured
Zed Editor, Reviewed: A Fast Code Editor That's Still Catching Up on Extensions Priya Narayanan · Backtrace
Author
Security & DevOps Specialist
11+ years experience
Marcus Oyelaran spent eleven years moving between platform and security teams, including four years as a security engineer embedded inside a DevOps org at a healthcare SaaS company handling PHI at scale. He's run more incident postmortems than he can count, and most of what he writes for Backtrace comes directly out of those postmortems: the secret that leaked through a build log, the IAM policy that was too permissive by one wildcard, the deploy that skipped a gate because someone was in a hurry. He holds an OSCP and spends an unreasonable amount of time arguing about supply chain security on internal Slack channels.
Tyrell Banks on software supply chain attacks: what actually matters for engineering teams making this call.
Marcus Oyelaran · · 6 min read
Tyrell Banks on secrets scanning tools: what actually matters for engineering teams making this call.
Marcus Oyelaran · · 6 min read
Tyrell Banks on software bill of materials SBOM: what actually matters for engineering teams making this call.
Marcus Oyelaran · · 6 min read
Kelsey Mabry on SAST vs DAST vs SCA: what actually matters for engineering teams making this call.
Marcus Oyelaran · · 6 min read
Derek Holloway on Docker image build time: what actually matters for engineering teams making this call.
Marcus Oyelaran · · 6 min read
Jordan Pike on least privilege access cloud: what actually matters for engineering teams making this call.
Marcus Oyelaran · · 6 min read
Derek Holloway on Kubernetes cost optimization: what actually matters for engineering teams making this call.
Marcus Oyelaran · · 6 min read
Derek Holloway on incident response runbook: what actually matters for engineering teams making this call.
Marcus Oyelaran · · 6 min read
Derek Holloway on GitHub Actions vs GitLab CI: what actually matters for engineering teams making this call.
Marcus Oyelaran · · 6 min read
Casey Lindqvist on feature flags best practices: what actually matters for engineering teams making this call.
Marcus Oyelaran · · 6 min read
Casey Lindqvist on blue-green vs canary deployment: what actually matters for engineering teams making this call.
Marcus Oyelaran · · 6 min read
Jordan Pike on API key rotation best practices: what actually matters for engineering teams making this call.
Marcus Oyelaran · · 6 min read
Recent searches
No results found
Your search did not match any results. Please try again.
Search is temporarily unavailable. Please check your connection and try again.
Get our best stories in your inbox. No spam, unsubscribe any time.
Thanks — you're on the list.