Supply Chain Attackers Escalate With GitHub Dependabot Impersonation
Armed with stolen developer passcodes, attackers have checked in changes to repositories under the automation feature's name in an attempt to escape notice.
The US government aims to support open source projects, while the European Union seeks to make open source projects liable for their software. Which approach will lead to more security?