Fifty Years of Open Source Software Supply Chain Security
Fifty Years of Open Source Software Supply Chain Security
Taming the Wild West of #ML: Practical Model Signing with #Sigstore
https://security.googleblog.com/2025/04/taming-wild-west-of-ml-practical-model.html
"When Covid hit in 2020, the diversification efforts sped up. The global pandemic — and manufacturing line shutdowns — made it painfully obvious that building everything in one place wasn’t the best idea. Then there was the toll from US inflation, but Apple held firm to its pricing strategy.
The latest tariffs promise to be the biggest test yet — especially because they go beyond China and extend to the very countries Apple has been shifting toward. As I detailed in a story this past week, these production hubs are all getting hit by the new tariffs:
- India, where Apple is increasingly building iPhones and AirPods, will have a 26% tariff.
- Vietnam, where the company now makes some AirPods, iPads, Apple Watches and Macs, will be hit with a 46% levy.
- Malaysia, where Apple is increasingly producing Macs, will have a 24% tariff.
- Thailand, where the company also makes some Macs, will get a 37% levy.
- Ireland, within the European Union, gets a 20% tariff. Apple produces some iMacs there.
- Indonesia, which will soon begin making AirTags and mesh for the AirPods Max headphones, gets a 32% tariff.
The latest tariffs will be 34% for China, bringing its total level to 54%. But the overall picture suggests Apple isn’t going to get as much benefit as hoped from diversifying away from that country. Apple will still be taking a hit on iPhones made in India, AirPods made in Vietnam and Macs made elsewhere in Asia.
There is still a chance that Cook can secure some sort of exemption or that the countries themselves will negotiate better terms. But assuming the levies are fully in place by April 9 as planned, Apple will have a big decision to make: Will it eat the costs of the tariffs, push suppliers to reduce prices, pass on the expense to customers or make further supply chain adjustments? My bet is that Apple will do a combination of all four."
Why Do Domestic Prices Rise with Tarriffs?
[#TRADESHOW] 2025 #EAC New #Energy & #Autonomous #Vehicle #Trade #Show will take place from June 4–6, 2025, at the #Hangzhou Grand #Exhibition #Center, #China. #Expo #event bridges the entire #automotive #supplychain, from raw #materials and #battery #tech to #OEMs, driving advancements in #sustainability, #safety, and #connectivity. https://cnbusinessforum.com/event/2025-eac-new-energy-autonomous-vehicle-trade-show-hangzhou/
A disruption in Taiwan's exports could hit US builders hard. Drywall needs 125 screws per 100 sq. ft., and most came from Taiwan last year. A business professor breaks down the impact on U.S. imports: https://theconversation.com/more-than-just-chips-chinese-threats-and-trump-tariffs-could-disrupt-lots-of-made-in-taiwan-imports-disappointing-us-builders-cyclists-and-golfers-alike-253729 #tariffs #supplychain
Average person will be 40% poorer if world warms by 4C
Experts say previous #economic models underestimated impact of #globalheating – as well as likely ‘cascading #supplychain disruptions’
Australian scientists study suggests average per person #GDP across the globe will be reduced by 16% even if warming is kept to 2C above pre-industrial levels. This is a much greater reduction than previous estimates, which found the reduction would be 1.4%.
https://www.theguardian.com/environment/2025/apr/01/average-person-will-be-40-poorer-if-world-warms-by-4c-new-research-shows #climate #climatechange
[#TRADESHOW] The LET-a #CeMAT #ASIA #EVENT 2025, a #flagship #exhibition for #intelligent #logistics and #automation, from May 21 to 23, 2025, at the #China #Import and #Export #Fair Complex, #Guangzhou. As a professional event in the #Guangdong-#HongKong-#Macao #GreaterBayArea and a Hannover CeMAT #brand exhibition, this expo is a must-attend for professionals in #smart logistics, #digital #manufacturing, and #SupplyChain solutions. https://cnbusinessforum.com/event/let-a-cemat-asia-event-2025/
[#TRADESHOW] 2025 #EAC New #Energy & #Autonomous #Vehicle #Trade #Show will take place from June 4–6, 2025, at the #Hangzhou Grand #Exhibition #Center, #China. #Expo #event bridges the entire #automotive #supplychain, from raw #materials and #battery #tech to #OEMs, driving advancements in #sustainability, #safety, and #connectivity. https://cnbusinessforum.com/event/2025-eac-new-energy-autonomous-vehicle-trade-show-hangzhou/
So with an #crazyweirdo in command, that talks about new #tariffs on average once per week if not more often, do you want to rely on products from such a country in your #supplychain ?
Want to buy a billion dollar war plane from the #usa when #weirdoinchief might decide next week that your maintenance contract (these go over 30+ years) is suspended because of your countries #diversity policy? Or because it allows "X" in the sex field in the passport? 6/6
GitHub CodeQL Actions Critical Supply Chain Vulnerability (CodeQLEAKED)
In today's Supply Chain News ...
Eleven oooold npm packages were hijacked to steal API keys. Wonder how many of them jise are just sitting on n someone's built pipeline with "latest" as the version parameter?
https://www.sonatype.com/blog/multiple-crypto-packages-hijacked-turned-into-info-stealers
h/t to SonaType for the top notch research.
Man, npm and supply chain security... seriously a never-ending story. Just caught an article about "ethers-provider2" and "ethers-providerz". Get this: these things are actually infecting packages you *already* have installed!
Speaking as a pentester, let me tell ya: you absolutely *have* to run regular checks. Your `package-lock.json`, `yarn.lock`... check 'em all! Trust me, SCA tools are worth their weight in gold in these situations. And listen up, people, MFA for your npm account? That's not some optional extra, it's a straight-up *MUST*!
I literally just had a client who thought, "Ah, npm's pretty safe, right?". Yeah, famous last words!
So, what're your most insane supply chain attack stories? Lay 'em on me!
[#TRADESHOW] The LET-a #CeMAT #ASIA #EVENT 2025, a #flagship #exhibition for #intelligent #logistics and #automation, from May 21 to 23, 2025, at the #China #Import and #Export #Fair Complex, #Guangzhou. As a professional event in the #Guangdong-#HongKong-#Macao #GreaterBayArea and a Hannover CeMAT #brand exhibition, this expo is a must-attend for professionals in #smart logistics, #digital #manufacturing, and #SupplyChain solutions. https://cnbusinessforum.com/event/let-a-cemat-asia-event-2025/
[#TRADESHOW] 2025 #EAC New #Energy & #Autonomous #Vehicle #Trade #Show will take place from June 4–6, 2025, at the #Hangzhou Grand #Exhibition #Center, #China. #Expo #event bridges the entire #automotive #supplychain, from raw #materials and #battery #tech to #OEMs, driving advancements in #sustainability, #safety, and #connectivity. https://cnbusinessforum.com/event/2025-eac-new-energy-autonomous-vehicle-trade-show-hangzhou/
Revolutionizing Logistics with SmidMart!
Track & Trace: Real-time tracking
Automation:quality checks & faster processes.
Insights: Data-driven decisions for efficiency
to know more :https://zurl.co/AVh9j
#LogisticsAutomation #AI #SmidMart #SupplyChain
#security vulnerability on #npm packages
https://www.reversinglabs.com/blog/malicious-npm-patch-delivers-reverse-shell
[#TRADESHOW] 2025 #EAC New #Energy & #Autonomous #Vehicle #Trade #Show will take place from June 4–6, 2025, at the #Hangzhou Grand #Exhibition #Center, #China. #Expo #event bridges the entire #automotive #supplychain, from raw #materials and #battery #tech to #OEMs, driving advancements in #sustainability, #safety, and #connectivity. https://cnbusinessforum.com/event/2025-eac-new-energy-autonomous-vehicle-trade-show-hangzhou/
Nerd question about the Port of Los Angeles: anyone have insight into what the contents of "recyclable plastics (293,218 TEUs)" imported in 2024 are? Is it nurdles? Is it just consumer goods made of plastic that are being labeled recyclable? ??
"Hands-On SBOM: Creating and Managing SBOMs for PHP Application Containers" will be Arne Blankerts #phpday25 #PHP #sbom #security #supplychain #devops
--------
phpday - 22nd edition
The annual gathering for developers, professionals, and PHP enthusiasts.
The conference is powered by @gruspVerona (Italy) |
May 15-16, 2025
Tickets https://bit.ly/41J6UP3