<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Supply-Chain on Nitzan's Blog</title><link>https://blog.nitzan.fyi/tags/supply-chain/</link><description>Recent content in Supply-Chain on Nitzan's Blog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 18 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.nitzan.fyi/tags/supply-chain/index.xml" rel="self" type="application/rss+xml"/><item><title>You Trust 1000 Strangers Every Time You Deploy</title><link>https://blog.nitzan.fyi/posts/you-trust-1000-strangers-every-time-you-deploy/</link><pubDate>Tue, 18 Aug 2026 00:00:00 +0000</pubDate><guid>https://blog.nitzan.fyi/posts/you-trust-1000-strangers-every-time-you-deploy/</guid><description>&lt;blockquote&gt;
&lt;p&gt;npm, PyPI, GitHub Actions, container registries — every layer of your supply chain was built on trust that no longer holds. The only question is whether you catch it before production or after.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Every modern application is mostly other people&amp;rsquo;s code. A typical project pulls in hundreds and thousands of transitive dependencies across npm, PyPI, Go modules, container base images, and GitHub Actions. &lt;strong&gt;Each one is a decision someone else made about what to run on your machine, in your CI, on your production servers&lt;/strong&gt;.&lt;/p&gt;</description></item></channel></rss>