<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: gcolella</title><link>https://news.ycombinator.com/user?id=gcolella</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 11 Oct 2026 06:02:40 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=gcolella" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by gcolella in "Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign"]]></title><description><![CDATA[
<p>Supply chain attacks via package managers are exactly the nightmare     
   scenario. A few months ago I had a production issue where a composer  
   dependency got silently nuked from our vendor/ — the package was        
   setasign/fpdf. Before restoring it, my first instinct was "did someone  
   compromise the repo?". Turned out to be local, but the 10 minutes 
   between discovery and confirmation were terrifying. Now we pin every    
   dependency by hash in composer.lock and review any change in it before  
   deployment. Still not enough — if the registry itself is compromised, 
   the hash pin saves you only from drive-by tampering, not from           
   poisoned-at-origin uploads. Feels like we need something like         
   Sigstore-level attestation for PHP/npm at minimum.</p>
]]></description><pubDate>Fri, 24 Apr 2026 11:52:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=47888958</link><dc:creator>gcolella</dc:creator><comments>https://news.ycombinator.com/item?id=47888958</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47888958</guid></item></channel></rss>