Fresher guidance and dependency updates
The website now reflects the latest supply-chain posts, while dependencies were updated to keep the platform current.
This release catches the website changelog up with the latest content and maintenance work. We added new writing on dormant maintainer accounts in RubyGems and ViteVenom’s import-time malware pattern, both focused on practical incident-response questions rather than headline-driven fear.
Behind the scenes, dependencies were updated to pick up current fixes and keep the platform moving with the ecosystem. That kind of maintenance is intentionally boring, but it is part of building a security product that stays healthy over time.
The website changelog also now tells a clearer story again: from vulnerability rescans, to better transitive dependency guidance, to public security portals, to CI-ready SBOM uploads, to the latest supply-chain research.