Recent developments in open source supply chain security have introduced enhanced monitoring and detection capabilities for package maintainers and developers. Trail of Bits is preparing Sigstore’s rekor-monitor for production, enabling developers to detect tampering and unauthorized use of their identities in the Rekor transparency log. This tool, funded by the OpenSSF, supports the new Rekor v2 log, certificate validation, and integration with The Update Framework (TUF), allowing maintainers to monitor for unexpected signing events and quickly identify potential compromises in their release process. Transparency logs like Rekor provide append-only, tamper-evident records, but require active monitoring to ensure trustworthiness, especially in the event of compromised identities.
Simultaneously, Deno 2.6 has introduced new supply chain security features, including a deno audit command that scans dependencies against GitHub's CVE database and integrates with Socket's Firewall API for real-time detection of malicious packages and supply chain risks. The Socket integration allows both unauthenticated and authenticated scanning modes, providing instant security scanning and the ability to enforce organizational security policies. These advancements reflect a broader trend toward proactive, behavior-based detection of supply chain threats, moving beyond traditional CVE-based vulnerability scanning to catch emerging risks such as typosquatting, malicious install scripts, and obfuscated code before they impact production environments.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Deno 2.6 added integration with Socket's Firewall API to provide real-time supply-chain threat detection from the CLI. The integration supports both unauthenticated and authenticated scanning modes so organizations can enforce security policies and get detailed threat analysis.
Deno 2.6 introduced a new 'deno audit' command to scan dependencies against GitHub's CVE database. The release also added granular script approval, minimum dependency age requirements, and faster typechecking via tsgo.
Trail of Bits reported improvements to rekor-monitor including support for the new Rekor v2 log, certificate validation, enhanced reliability, and integration with The Update Framework. The project also added a reusable GitHub workflow to make transparency-log monitoring easier to adopt.
OpenSSF funded work to prepare Sigstore's rekor-monitor for production use so package maintainers can detect tampering and unauthorized use of their identities in the Rekor transparency log. The effort included contributions from Sigstore maintainers as part of broader open source supply-chain security work.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.