SECURITY CIPHER · BLOG
DevSecOps
Posts from Security Cipher.
Software Supply Chain Security in 2026: Packages, Pipelines, and Provenance
Most teams still treat supply chain security like a compliance checkbox: generate an SBOM once a quarter, turn on Dependabot, call it…
I Ran Codex Security on a Shop API Lab: 14 Bugs, $1.64, Full Playbook
Hands-on OpenAI Codex Security CLI guide: scan a Flask shop API, get 14 findings, threat model, remediations, GitHub bulk-scan, and a real…