<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Supply Chain - Developers Digest</title>
    <link>https://www.developersdigest.tech/blog/tags/supply-chain</link>
    <description>Articles about Supply Chain on Developers Digest</description>
    <language>en</language>
    <lastBuildDate>Tue, 12 May 2026 16:53:31 GMT</lastBuildDate>
    <atom:link href="https://www.developersdigest.tech/blog/tags/supply-chain/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title><![CDATA[TanStack's npm Compromise Is the CI Lesson Agent Teams Needed]]></title>
      <link>https://www.developersdigest.tech/blog/npm-supply-chain-trust-boundaries-ai-agents</link>
      <guid isPermaLink="true">https://www.developersdigest.tech/blog/npm-supply-chain-trust-boundaries-ai-agents</guid>
      <description><![CDATA[The TanStack npm incident was not just a package-security story. It was a reminder that AI agent workflows inherit every weak trust boundary in CI.]]></description>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <category>Security</category>
      <category>AI Agents</category>
      <category>GitHub Actions</category>
      <category>Developer Workflow</category>
      <category>Supply Chain</category>
      <enclosure url="https://www.developersdigest.tech/images/blog/npm-supply-chain-trust-boundaries-ai-agents/hero.webp" type="image/webp" />
    </item>
  </channel>
</rss>