LOADING...

That’s a wrap: GitHub Innovation Graph in 2024
January 23, 2025

That’s a wrap: GitHub Innovation Graph in 2024

This is our first GitHub Innovation Graph data release in 2025 and our first data release after celebrating the Innovation Graph’s first birthday, so we’d like to reflect a bit on how things have gone so far and share our
By
Attacks on Maven proxy repositories
January 22, 2025

Attacks on Maven proxy repositories

As someone who’s been breaking the security of Java applications for many years, I was always curious about the supply chain attacks on Java libraries. In 2019, I accidentally discovered an arbitrary file read vulnerability on search.maven.org, a website that
By