<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[A useful reminder from the last few days, I think: security tooling is part of the attack surface - maybe that aren&#x27;t news.]]></title><description><![CDATA[<p>A useful reminder from the last few days, I think: security tooling is part of the attack surface - maybe that aren't news.</p><p>But: If scanners, GitHub Actions or container images get compromised, this is not just a supply chain problem on paper. It hits the exact layer we **usually** trust to keep the rest safe.</p><p>Feels like a good time to ask: where are we still too loose on pinning, still trusting `latest`, or still assuming third-party actions are probably fine?</p><p>I think we need to find the right balance between `latest` and waiting days or even weeks to update a component (especially if it's an security patch).</p><p><a href="https://infosec.exchange/tags/axios" rel="tag">#<span>axios</span></a> <a href="https://infosec.exchange/tags/trivy" rel="tag">#<span>trivy</span></a> <a href="https://infosec.exchange/tags/supplychain" rel="tag">#<span>supplychain</span></a> <a href="https://infosec.exchange/tags/supplychainsecurity" rel="tag">#<span>supplychainsecurity</span></a> <a href="https://infosec.exchange/tags/cybersecurity" rel="tag">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/security" rel="tag">#<span>security</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/4d697126-0fc0-4443-a250-008d8e81d1af/a-useful-reminder-from-the-last-few-days-i-think-security-tooling-is-part-of-the-attack-surface-maybe-that-aren-t-news.</link><generator>RSS for Node</generator><lastBuildDate>Mon, 06 Apr 2026 06:37:48 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/4d697126-0fc0-4443-a250-008d8e81d1af.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 01 Apr 2026 16:01:44 GMT</pubDate><ttl>60</ttl></channel></rss>