{"id":5123,"date":"2026-09-23T13:13:21","date_gmt":"2026-09-23T13:13:21","guid":{"rendered":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/09\/23\/cycode-extends-devsecops-reach-to-software-packages-developers-download\/"},"modified":"2026-09-23T13:13:21","modified_gmt":"2026-09-23T13:13:21","slug":"cycode-extends-devsecops-reach-to-software-packages-developers-download","status":"publish","type":"post","link":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/09\/23\/cycode-extends-devsecops-reach-to-software-packages-developers-download\/","title":{"rendered":"Cycode Extends DevSecOps Reach to Software Packages Developers Download"},"content":{"rendered":"<div><img data-opt-id=1726625058  fetchpriority=\"high\" decoding=\"async\" width=\"770\" height=\"330\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/09\/Cycode2.jpg\" class=\"attachment-large size-large wp-post-image\" alt=\"\" \/><\/div>\n<p><img data-opt-id=1659688490  fetchpriority=\"high\" decoding=\"async\" width=\"150\" height=\"150\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/09\/Cycode2-150x150.jpg\" class=\"attachment-thumbnail size-thumbnail wp-post-image\" alt=\"\" \/><\/p>\n<p>Cycode today revealed it is providing early access to an extension of its platform for securing software supply chains that prevents developers from downloading malicious or suspicious software packages onto their workstations.<\/p>\n<p>A Workstation Protection capability that has been added to that platform enables DevSecOps teams to apply policies and controls that prevent developers from downloading potentially malicious instances of software packages from a software repository.<\/p>\n<p>Specifically, the Cycode agentic development lifecycle (ADLC) Protection platform applies two controls in real time. The first inspects software packages against a threat intelligence feed to prevent downloads of known malicious software packages. The second will automatically prevent the download of any software package that has been too recently updated on the assumption that there has not been enough time to properly vet it, otherwise known as a cool down period.<\/p>\n<p>Devin Maguire, senior product marketing manager for Cycode, said that now cybercriminals are more aggressively poisoning upstream sources of code, the need to apply controls at the workstation level has become critical. Designed to be installed as part of the Mobile Device Management module that Cycode already provides, those controls can be applied with no additional console needing to be added to an existing DevSecOps workflow based on the Cycode platform, he added.<\/p>\n<p><img data-opt-id=497159062  data-opt-src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/09\/Cycode1.jpg\"  decoding=\"async\" class=\"alignnone size-full wp-image-198391\" src=\"data:image/svg+xml,%3Csvg%20viewBox%3D%220%200%20100%%20100%%22%20width%3D%22100%%22%20height%3D%22100%%22%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Crect%20width%3D%22100%%22%20height%3D%22100%%22%20fill%3D%22transparent%22%2F%3E%3C%2Fsvg%3E\" alt=\"\" width=\"2010\" height=\"1350\" \/><\/p>\n<p>Most application developers routinely download software components from multiple software repositories. Cybercriminals are now targeting those repositories in the hopes of injecting malware into a downstream application that they can later activate. That tactic has become even more pernicious because cybercriminals are also now starting to use malicious prompts to trick AI coding agents into downloading malicious software packages.<\/p>\n<p>Unfortunately, application developers don\u2019t always scan each package for malware before incorporating it into their codebase. Hopefully, that malware will be discovered at some point before that code is incorporated into an application running in a production environment. Cycode, however, is making a case for applying controls that prevent malicious software packages from ever entering the software supply chain in the first place, said Maguire.<\/p>\n<p>Mitch Ashley, vice president and practice lead for software lifecycle engineering at <a href=\"https:\/\/futurumgroup.com\/\" target=\"_blank\" rel=\"noopener\">The Futurum Group<\/a>, said package policy is now an agent governance decision. There is no doubt coding agents increase software supply chain risks on the developer workstation, he added. When an agent installs packages on its own, install time becomes the first control point, well before a scanner sees the code, noted Ashley.<\/p>\n<p>It\u2019s not clear how aggressively DevSecOps teams are now moving to lock down software supply chains but as the number of attacks aimed at upstream repositories continues to increase it\u2019s now more a question of how soon they will revisit those workflows. Cybersecurity teams, in particular, have become more acutely aware of the fact that the software supply chain created to build applications has become a soft underbelly that adversaries now regularly target. As such, they are asking more pointed questions about how applications are actually constructed.<\/p>\n<p>Hopefully, the poisoning of the software repositories that house software packages will eventually be resolved at the source. In the meantime, it\u2019s up to each DevSecOps team to lock down their software supply chain in a way that doesn\u2019t wind up slowing down the pace at which applications are being built by, for example, trying to limit access to any and all software packages that were developed outside the organization.<\/p>\n<p><a href=\"https:\/\/devops.com\/cycode-extends-devsecops-reach-to-software-packages-developers-download\/\" target=\"_blank\" class=\"feedzy-rss-link-icon\">Read More<\/a><\/p>\n<p>\u200b<\/p>","protected":false},"excerpt":{"rendered":"<p>Cycode today revealed it is providing early access to an extension of its platform for securing software supply chains that [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":5124,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[5],"tags":[],"class_list":["post-5123","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-devops"],"_links":{"self":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/5123","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/comments?post=5123"}],"version-history":[{"count":0,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/5123\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media\/5124"}],"wp:attachment":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media?parent=5123"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/categories?post=5123"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/tags?post=5123"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}