{"@attributes":{"version":"2.0"},"channel":{"title":"Commit \u2014 Behavioral Trust for Open Source","description":"Essays and research on behavioral commitment, trust infrastructure, and the future of signals that cannot be faked.","link":"https:\/\/getcommit.dev\/","language":"en-us","item":[{"title":"PostCSS Adopted Staged Publishing. 685M Weekly Downloads Now Gated.","link":"https:\/\/getcommit.dev\/blog\/postcss-nanoid-staged-publishing\/","guid":"https:\/\/getcommit.dev\/blog\/postcss-nanoid-staged-publishing\/","description":"Andrey Sitnik pushed back on CI provenance, shipped Staged Publishing on nanoid within hours, then followed through on PostCSS, browserslist, and autoprefixer. 685M weekly downloads secured in 9 days.","pubDate":"Sat, 27 Jun 2026 00:00:00 GMT"},{"title":"Hono Just Adopted Staged Publishing. 50M Weekly Downloads, 33 Hours After the Issue.","link":"https:\/\/getcommit.dev\/blog\/hono-staged-publishing-adopted\/","guid":"https:\/\/getcommit.dev\/blog\/hono-staged-publishing-adopted\/","description":"Hono moved from CI-direct npm publishing to npm Staged Publishing on June 22, 2026. Issue filed June 21, PR merged June 22. The release.yml diff is one line. 50M weekly downloads now sit behind a human approval gate.","pubDate":"Wed, 24 Jun 2026 00:00:00 GMT"},{"title":"OIDC Provenance Didn't Save TanStack or Red Hat. npm Staged Publishing Is the Missing Gate.","link":"https:\/\/getcommit.dev\/blog\/staged-publishing-detection\/","guid":"https:\/\/getcommit.dev\/blog\/staged-publishing-detection\/","description":"TanStack (May 2026) and Red Hat (June 2026) were both compromised through their CI pipelines. Both had valid SLSA provenance. npm Staged Publishing adds a human approval gate that provenance can't provide. Commit now detects it. First adopters: nanoid, nanospy, preact.","pubDate":"Fri, 19 Jun 2026 00:00:00 GMT"},{"title":"How fast-xml-parser Got OIDC Provenance in 12 Hours","link":"https:\/\/getcommit.dev\/blog\/fast-xml-parser-provenance-case-study\/","guid":"https:\/\/getcommit.dev\/blog\/fast-xml-parser-provenance-case-study\/","description":"Behavioral scoring flagged fast-xml-parser as CRITICAL: 88M downloads\/week, single publisher, no provenance. The maintainer shipped OIDC provenance in 12 hours. Here's what happened.","pubDate":"Thu, 18 Jun 2026 00:00:00 GMT"},{"title":"One npm Account Publishes 964 Million Downloads Per Week. None Have Provenance.","link":"https:\/\/getcommit.dev\/blog\/one-account-964m-downloads\/","guid":"https:\/\/getcommit.dev\/blog\/one-account-964m-downloads\/","description":"The ai npm account controls postcss, nanoid, browserslist, caniuse-lite, autoprefixer, and more. All flagged CRITICAL. Zero OIDC provenance. One stolen credential away from the biggest npm incident yet.","pubDate":"Thu, 18 Jun 2026 00:00:00 GMT"},{"title":"A LinkedIn Recruiter Got a Developer to npm install a Backdoor. We Scanned the Repo.","link":"https:\/\/getcommit.dev\/blog\/linkedin-recruiter-npm-backdoor\/","guid":"https:\/\/getcommit.dev\/blog\/linkedin-recruiter-npm-backdoor\/","description":"The malicious GitHub repo had a prepare lifecycle script that executed arbitrary remote commands on npm install. We reconstructed the dependency profile. Here's what the trust signals showed.","pubDate":"Tue, 16 Jun 2026 00:00:00 GMT"},{"title":"978 npm Downloads Per Week. Zero Organic Signups.","link":"https:\/\/getcommit.dev\/blog\/978-downloads-zero-signups\/","guid":"https:\/\/getcommit.dev\/blog\/978-downloads-zero-signups\/","description":"Commit's CLI has 978 weekly npm downloads, 21 funnels, 18 IPs that hit the inline signup prompt in the last 7 days, and 0 organic signups in 90 days. Here is the live admin data, what I think went wrong, and what shipped today to test the diagnosis.","pubDate":"Sat, 20 Jun 2026 00:00:00 GMT"},{"title":"A Dormant npm Account Just Compromised 141 Mastra Packages in 88 Minutes","link":"https:\/\/getcommit.dev\/blog\/mastra-dormant-publisher-attack\/","guid":"https:\/\/getcommit.dev\/blog\/mastra-dormant-publisher-attack\/","description":"The @mastra scope was hijacked through a forgotten contributor account with stale publish access. The injected dependency scored 30 on Commit. The package it cloned scored 90. That 60-point gap was readable before the attack.","pubDate":"Wed, 17 Jun 2026 00:00:00 GMT"},{"title":"NVIDIA SkillSpector and the Runtime Trust Gap","link":"https:\/\/getcommit.dev\/blog\/nvidia-skillspector-runtime-trust-gap\/","guid":"https:\/\/getcommit.dev\/blog\/nvidia-skillspector-runtime-trust-gap\/","description":"NVIDIA open-sourced a static security scanner for AI agent skills. We pointed it at 30 production skills and got CRITICAL\/100. Then we read the findings. Eight of eleven HIGHs were structural false positives. Static analysis can't see trust context, and that's not a bug.","pubDate":"Tue, 16 Jun 2026 00:00:00 GMT"},{"title":"Atomic Arch Targets Bun. The Entry Point Was AUR.","link":"https:\/\/getcommit.dev\/blog\/atomic-arch-targets-bun\/","guid":"https:\/\/getcommit.dev\/blog\/atomic-arch-targets-bun\/","description":"1,500 Arch Linux packages hijacked to inject three malicious npm dependencies. Wave 2 adds Bun-specific install paths \u2014 the runtime check explicitly branches for Bun. The eBPF rootkit hides everything except the npm registry record behavioral scoring reads.","pubDate":"Sun, 14 Jun 2026 00:00:00 GMT"},{"title":"Snyk Scores Lodash 86. We Score It CRITICAL.","link":"https:\/\/getcommit.dev\/blog\/snyk-scores-lodash-86-we-score-it-critical\/","guid":"https:\/\/getcommit.dev\/blog\/snyk-scores-lodash-86-we-score-it-critical\/","description":"Snyk's Package Health Score gives lodash 86\/100 and labels it HEALTHY. Commit flags it CRITICAL. Same package, opposite conclusions. The difference: one npm publisher controls 162M weekly downloads \u2014 the structural signal behind every major 2026 supply chain attack.","pubDate":"Sun, 14 Jun 2026 00:00:00 GMT"},{"title":"Snyk Scores Chalk 81. We Score It CRITICAL.","link":"https:\/\/getcommit.dev\/blog\/snyk-scores-chalk-81-we-score-it-critical\/","guid":"https:\/\/getcommit.dev\/blog\/snyk-scores-chalk-81-we-score-it-critical\/","description":"Snyk's Package Health Score gives chalk 81\/100. Commit flags it CRITICAL. Same package, opposite conclusions. The difference: publisher concentration risk, the signal behind every major npm attack in 2026.","pubDate":"Sun, 14 Jun 2026 00:00:00 GMT"},{"title":"80% of Agent Skills Lie About What They Do","link":"https:\/\/getcommit.dev\/blog\/unit42-80-percent-agent-skills-lie\/","guid":"https:\/\/getcommit.dev\/blog\/unit42-80-percent-agent-skills-lie\/","description":"Palo Alto Unit42 crawled 49,943 OpenClaw skills and found 80% have behavioral deviations from their declared intent. Then they admitted their own scanner can't catch the dangerous tail. The clearest third-party evidence yet that agent behavioral monitoring has to happen at runtime.","pubDate":"Sun, 14 Jun 2026 00:00:00 GMT"},{"title":"1,579 AUR Packages Were Taken Over Through the Adoption Process. The Bypass Was the Process.","link":"https:\/\/getcommit.dev\/blog\/aur-1579-packages-adoption-bypass\/","guid":"https:\/\/getcommit.dev\/blog\/aur-1579-packages-adoption-bypass\/","description":"Arch Linux's AUR has a documented mechanism for orphaned packages to be adopted by new maintainers. Last week attackers used it as designed. Number started at 400. Ended at 1,579. The defense missing in every ecosystem is the same one: behavioral history that follows the human, not the package.","pubDate":"Sat, 13 Jun 2026 00:00:00 GMT"},{"title":"The Worm Has Been Public for 31 Days. Two Derivatives Have Shipped.","link":"https:\/\/getcommit.dev\/blog\/mini-shai-hulud-source-code-public\/","guid":"https:\/\/getcommit.dev\/blog\/mini-shai-hulud-source-code-public\/","description":"TeamPCP open-sourced their self-propagating npm worm on May 12. Within a month, Red Hat Miasma (Jun 1) and Phantom Gyp (Jun 3) had forked it \u2014 each finding a new install-time bypass the previous defense couldn't survive. The target profile inverted: from 91-score TanStack to 28-score awaitly. Here's the pattern, and what the next derivative looks like.","pubDate":"Fri, 12 Jun 2026 00:00:00 GMT"},{"title":"Agent Phishing: The Attack Your Identity Stack Misses","link":"https:\/\/getcommit.dev\/blog\/agent-phishing-identity-stack\/","guid":"https:\/\/getcommit.dev\/blog\/agent-phishing-identity-stack\/","description":"Varonis proved it: an enterprise AI agent forwarded AWS keys and a $1.28M customer list to an attacker who sent two casual emails. The agent had valid credentials and passed every technical check. Only 7% of security teams believe they'd catch it.","pubDate":"Thu, 11 Jun 2026 00:00:00 GMT"},{"title":"57 Packages Compromised Without a Single Lifecycle Script. The binding.gyp Bypass Is Here.","link":"https:\/\/getcommit.dev\/blog\/phantom-gyp-binding-gyp-bypass\/","guid":"https:\/\/getcommit.dev\/blog\/phantom-gyp-binding-gyp-bypass\/","description":"The Phantom Gyp technique ships a weaponized binding.gyp that triggers code execution during npm install. No preinstall, no postinstall \u2014 bypasses every lifecycle script monitor. 57 packages, 286 malicious versions, under two hours.","pubDate":"Wed, 10 Jun 2026 00:00:00 GMT"},{"title":"IronWorm Commits as 'claude.' It Steals Your Anthropic and OpenAI Keys.","link":"https:\/\/getcommit.dev\/blog\/ironworm-rust-malware-targets-ai-credentials\/","guid":"https:\/\/getcommit.dev\/blog\/ironworm-rust-malware-targets-ai-credentials\/","description":"37 npm packages infected with a Rust-based infostealer that hides behind an eBPF rootkit, talks over Tor, and self-propagates through npm's Trusted Publishing. The commit author on every malicious push: claude@users.noreply.github.com.","pubDate":"Sat, 06 Jun 2026 00:00:00 GMT"},{"title":"TrapDoor Hit npm, PyPI, and Crates.io at Once. Then It Poisoned Your AI Assistant.","link":"https:\/\/getcommit.dev\/blog\/trapdoor-ai-assistant-poisoning\/","guid":"https:\/\/getcommit.dev\/blog\/trapdoor-ai-assistant-poisoning\/","description":"34 malicious packages across three ecosystems. Every one scored 15 or lower. The new part: zero-width Unicode instructions hidden in .cursorrules and CLAUDE.md, designed to turn your coding assistant into an exfiltration tool.","pubDate":"Sat, 06 Jun 2026 00:00:00 GMT"},{"title":"An IETF Draft Specifies Trust Scoring for AI Agents. Five Dimensions, Five Tiers, One Implementation Gap.","link":"https:\/\/getcommit.dev\/blog\/ietf-agent-payment-trust-draft\/","guid":"https:\/\/getcommit.dev\/blog\/ietf-agent-payment-trust-draft\/","description":"A March 2026 IETF internet-draft specifies behavioral trust scoring for AI agent payments. 0\u2013100 score, L0\u2013L4 spend tiers, public cross-org query API. The category got a protocol document. The implementation is still the whole thing.","pubDate":"Wed, 03 Jun 2026 00:00:00 GMT"},{"title":"32 Red Hat Packages Had Valid Provenance. All 32 Were Compromised.","link":"https:\/\/getcommit.dev\/blog\/redhat-miasma-provenance-bypass\/","guid":"https:\/\/getcommit.dev\/blog\/redhat-miasma-provenance-bypass\/","description":"The Miasma attack hijacked 32 @redhat-cloud-services npm packages through a compromised GitHub account. SLSA provenance attestations were valid on every malicious version. Provenance tells you who published. It doesn't tell you whether to trust them.","pubDate":"Mon, 01 Jun 2026 00:00:00 GMT"},{"title":"14 Typosquatted Packages in 4 Hours. Every One Had Zero Behavioral History.","link":"https:\/\/getcommit.dev\/blog\/microsoft-14-typosquatted-packages\/","guid":"https:\/\/getcommit.dev\/blog\/microsoft-14-typosquatted-packages\/","description":"Microsoft found 14 malicious npm packages impersonating OpenSearch and Elasticsearch. They stole AWS credentials, Vault tokens, and npm publish keys. Behavioral scoring would have flagged all of them on install.","pubDate":"Mon, 01 Jun 2026 00:00:00 GMT"},{"title":"FastAPI Was Flagged as Malware Last Week. It Wasn't.","link":"https:\/\/getcommit.dev\/blog\/osv-157-false-positives\/","guid":"https:\/\/getcommit.dev\/blog\/osv-157-false-positives\/","description":"OSV withdrew 157 malware reports after automated false positives hit FastAPI, Strawberry GraphQL, and dozens of other legitimate packages. Behavioral signals don't have false positives.","pubDate":"Sun, 31 May 2026 00:00:00 GMT"},{"title":"I Scored Every Compromised npm Package From May 2026. Four Out of Five Attacks Were Predictable.","link":"https:\/\/getcommit.dev\/blog\/may-2026-npm-attacks-roundup\/","guid":"https:\/\/getcommit.dev\/blog\/may-2026-npm-attacks-roundup\/","description":"Five major npm supply chain attacks in three weeks. I scored every compromised package. The data says one thing clearly: most attacks follow the same structural pattern.","pubDate":"Sat, 30 May 2026 00:00:00 GMT"},{"title":"Your AI Coding Assistant Is Now a Supply Chain Attack Surface","link":"https:\/\/getcommit.dev\/blog\/cursor-hook-supply-chain-gate\/","guid":"https:\/\/getcommit.dev\/blog\/cursor-hook-supply-chain-gate\/","description":"Cursor agents install npm, pip, cargo, and Go packages on your behalf. That's new attack surface. poc hook intercepts every install before it runs.","pubDate":"Fri, 29 May 2026 00:00:00 GMT"},{"title":"637 npm Packages Compromised in 39 Minutes. The Malware Installs a Claude Code SessionStart Hook.","link":"https:\/\/getcommit.dev\/blog\/shai-hulud-claude-code-hook\/","guid":"https:\/\/getcommit.dev\/blog\/shai-hulud-claude-code-hook\/","description":"The Shai-Hulud worm stole npm tokens and republished packages autonomously. One of its persistence mechanisms: a Claude Code SessionStart hook in your .claude\/settings.json.","pubDate":"Mon, 25 May 2026 00:00:00 GMT"},{"title":"Five Open PRs. drizzle-kit Still Ships @esbuild-kit\/esm-loader.","link":"https:\/\/getcommit.dev\/blog\/drizzle-kit-stale-transitive-dep\/","guid":"https:\/\/getcommit.dev\/blog\/drizzle-kit-stale-transitive-dep\/","description":"drizzle-kit scores 83 on its own. It transitively pulls in @esbuild-kit\/esm-loader: archived on GitHub, single maintainer, last published 981 days ago, 7.5M weekly downloads. Five community PRs to drop it have been open for up to 18 months. None merged.","pubDate":"Mon, 25 May 2026 00:00:00 GMT"},{"title":"Stripe and Google Cloud Storage Are Both CRITICAL on npm","link":"https:\/\/getcommit.dev\/blog\/stripe-google-cloud-critical\/","guid":"https:\/\/getcommit.dev\/blog\/stripe-google-cloud-critical\/","description":"stripe has 12M downloads\/week and 1 npm publisher. @google-cloud\/storage has 12M\/week and 1 publisher. AWS S3 SDK has 29M\/week and 2 publishers. Company reputation doesn't fix credential concentration.","pubDate":"Sun, 24 May 2026 00:00:00 GMT"},{"title":"npm Supply Chain Audit: The Checklist Most Teams Stop Too Early","link":"https:\/\/getcommit.dev\/blog\/npm-supply-chain-audit-checklist\/","guid":"https:\/\/getcommit.dev\/blog\/npm-supply-chain-audit-checklist\/","description":"Most npm supply chain audits stop at npm audit and Socket. There's a third layer \u2014 structural risk scoring \u2014 that identifies high-value targets before any attack occurs. Here's the complete checklist.","pubDate":"Fri, 22 May 2026 00:00:00 GMT"},{"title":"node-ipc Had a 69 Trust Score Before It Got Hacked. TanStack Had 91.","link":"https:\/\/getcommit.dev\/blog\/two-attacks-one-week\/","guid":"https:\/\/getcommit.dev\/blog\/two-attacks-one-week\/","description":"Two npm supply chain attacks hit the same week in May 2026. One was predictable from behavioral signals. One wasn't. That difference is the entire point of behavioral supply chain scoring.","pubDate":"Thu, 21 May 2026 00:00:00 GMT"},{"title":"Mini Shai-Hulud Didn't Need Your Maintainer's Password","link":"https:\/\/getcommit.dev\/blog\/tanstack-mini-shai-hulud-behavioral-analysis\/","guid":"https:\/\/getcommit.dev\/blog\/tanstack-mini-shai-hulud-behavioral-analysis\/","description":"On May 11, 84 malicious @tanstack artifacts were published using TanStack's own legitimate OIDC identity. No stolen credentials. The attacker extracted tokens from GitHub Actions runner memory after poisoning the build cache \u2014 and left behavioral traces in public repos the whole time.","pubDate":"Tue, 19 May 2026 00:00:00 GMT"},{"title":"npm Trusted Publishing is a column now","link":"https:\/\/getcommit.dev\/blog\/npm-trusted-publishing-provenance\/","guid":"https:\/\/getcommit.dev\/blog\/npm-trusted-publishing-provenance\/","description":"v1.7.0 of proof-of-commitment adds a Provenance column: \ud83d\udd10 verified vs \u2014 for every package you scan. Here's what Trusted Publishing actually is, how to set it up, and what the data shows.","pubDate":"Sat, 16 May 2026 00:00:00 GMT"},{"title":"Seven days our CLI silently lied to 297 users","link":"https:\/\/getcommit.dev\/blog\/critical-flag-silent-regression\/","guid":"https:\/\/getcommit.dev\/blog\/critical-flag-silent-regression\/","description":"From May 9 to May 16, every CRITICAL package scanned by proof-of-commitment showed as HEALTHY. 297 weekly users. Zero error. One wrong string comparison \u2014 Array.includes exact-match failed when the API changed to full-text flag format. v1.7.0 fixes it.","pubDate":"Sat, 16 May 2026 00:00:00 GMT"},{"title":"Compliance Theater Is Losing to Behavioral Proof","link":"https:\/\/getcommit.dev\/blog\/compliance-theater-behavioral-proof\/","guid":"https:\/\/getcommit.dev\/blog\/compliance-theater-behavioral-proof\/","description":"The SOC2 thread and the AI strip mining thread hit HN the same day. One founder can't get the stamp because they have no employees. The other watches LLMs flood their inbox with real vulnerabilities at 4x the old rate. Same root cause: we're verifying declarations instead of measuring behavior.","pubDate":"Sat, 16 May 2026 00:00:00 GMT"},{"title":"I Added OpenSSF Scorecard to getcommit.dev. The Results Tell Two Different Stories.","link":"https:\/\/getcommit.dev\/blog\/scorecard-vs-behavioral\/","guid":"https:\/\/getcommit.dev\/blog\/scorecard-vs-behavioral\/","description":"OpenSSF Scorecard measures process security. Behavioral signals measure publisher concentration. Both matter. Here's what happens when you combine them on npm's most critical packages \u2014 and why the axios attack proved they answer different questions.","pubDate":"Fri, 15 May 2026 00:00:00 GMT"},{"title":"Scan any GitHub repo for supply chain risk in one click","link":"https:\/\/getcommit.dev\/blog\/github-repo-scanner\/","guid":"https:\/\/getcommit.dev\/blog\/github-repo-scanner\/","description":"Paste a GitHub URL. Get behavioral trust scores for every dependency instantly \u2014 publisher concentration, release consistency, contributor depth. No install, no account.","pubDate":"Thu, 14 May 2026 00:00:00 GMT"},{"title":"Half of npm's Top Packages Don't Use Trusted Publishing","link":"https:\/\/getcommit.dev\/blog\/trusted-publishing-adoption\/","guid":"https:\/\/getcommit.dev\/blog\/trusted-publishing-adoption\/","description":"Commit now detects npm Trusted Publishing (OIDC provenance) in every package score. The data: minimatch, chalk, lodash, express, react still publish via personal tokens. Build tools adopted. Utility packages didn't.","pubDate":"Thu, 14 May 2026 00:00:00 GMT"},{"title":"npm audit ships yesterday's risk. Here's how to measure tomorrow's.","link":"https:\/\/getcommit.dev\/blog\/transitive-risk-methodology\/","guid":"https:\/\/getcommit.dev\/blog\/transitive-risk-methodology\/","description":"A depth-2 supply chain audit methodology, run against five widely-used npm packages. The metric: weekly downloads concentrated behind single-person publish credentials across the transitive tree.","pubDate":"Wed, 13 May 2026 00:00:00 GMT"},{"title":"I scored the top packages in npm, PyPI, Cargo, and Go. One vulnerability pattern dominates three of them.","link":"https:\/\/getcommit.dev\/blog\/four-ecosystems-one-vulnerability\/","guid":"https:\/\/getcommit.dev\/blog\/four-ecosystems-one-vulnerability\/","description":"Same tool, same methodology, four ecosystems. 5.2 billion weekly downloads across npm, PyPI, and Cargo share a single structural weakness: sole-publisher accounts. Go doesn't have it. The difference is architectural.","pubDate":"Sat, 09 May 2026 00:00:00 GMT"},{"title":"I scanned 20 top Go modules. Zero scored CRITICAL. Here's why.","link":"https:\/\/getcommit.dev\/blog\/go-supply-chain-different-risk\/","guid":"https:\/\/getcommit.dev\/blog\/go-supply-chain-different-risk\/","description":"After finding publisher-concentration risk across npm, PyPI, and Cargo, Go was the first ecosystem where the structural pattern didn't appear. The risk model is different \u2014 and so are the failure modes.","pubDate":"Sat, 09 May 2026 00:00:00 GMT"},{"title":"Your pnpm monorepo has 4 CRITICAL packages. Here's how to find them in 10 seconds.","link":"https:\/\/getcommit.dev\/blog\/pnpm-monorepo-supply-chain-audit\/","guid":"https:\/\/getcommit.dev\/blog\/pnpm-monorepo-supply-chain-audit\/","description":"I scanned a pnpm workspace with 4 packages. 4 of the 10 unique dependencies flagged CRITICAL \u2014 single npm publisher, tens of millions of weekly downloads each. The monorepo aggregate view surfaces risks that per-package scans miss.","pubDate":"Sat, 09 May 2026 00:00:00 GMT"},{"title":"serde has 13M weekly downloads and one crate owner. Rust's supply chain risk looks like npm's.","link":"https:\/\/getcommit.dev\/blog\/cargo-supply-chain-risk\/","guid":"https:\/\/getcommit.dev\/blog\/cargo-supply-chain-risk\/","description":"I scanned the 20 most-downloaded Rust crates. 11 came back CRITICAL \u2014 single crates.io owner, millions of weekly downloads. Five of those are all owned by the same person.","pubDate":"Fri, 08 May 2026 00:00:00 GMT"},{"title":"AI Slop Is a Commitment Problem","link":"https:\/\/getcommit.dev\/blog\/ai-slop-commitment-problem\/","guid":"https:\/\/getcommit.dev\/blog\/ai-slop-commitment-problem\/","description":"The effort proxy broke. LLMs made 200 plausible words cost nothing. The fix isn't effort-detection \u2014 it's commitment-measurement: behavioral signals that compound over time and can't be faked.","pubDate":"Fri, 08 May 2026 00:00:00 GMT"},{"title":"Anthropic's Models Know When They're Being Watched","link":"https:\/\/getcommit.dev\/blog\/evaluation-awareness\/","guid":"https:\/\/getcommit.dev\/blog\/evaluation-awareness\/","description":"Evaluation awareness is now a measured property of frontier AI. Claude Haiku 4.5 showed awareness in 9% of test scenarios despite active filtering. The behavioral trust problem just got empirical.","pubDate":"Thu, 07 May 2026 00:00:00 GMT"},{"title":"certifi has 350M weekly downloads and one publisher. It handles your SSL certificates.","link":"https:\/\/getcommit.dev\/blog\/python-supply-chain-risk\/","guid":"https:\/\/getcommit.dev\/blog\/python-supply-chain-risk\/","description":"I ran the same supply chain analysis on Python that I did on npm. The findings are different \u2014 and in some ways worse. Eight CRITICAL packages, 2.5 billion weekly downloads behind sole-publisher accounts, and most of them are transitive dependencies you didn't install.","pubDate":"Mon, 04 May 2026 00:00:00 GMT"},{"title":"Behavioral Trust Without Surveillance Infrastructure","link":"https:\/\/getcommit.dev\/blog\/behavioral-trust-vs-surveillance\/","guid":"https:\/\/getcommit.dev\/blog\/behavioral-trust-vs-surveillance\/","description":"Persona's age verification SDK runs 269 behavioral checks, tracks you with FingerprintJS for 365 days, and sends raw signals to servers backed by Founders Fund. The behavioral signals are legitimate. The architecture isn't inevitable.","pubDate":"Thu, 30 Apr 2026 00:00:00 GMT"},{"title":"Express depends on escape-html. It hasn't been updated since 2015.","link":"https:\/\/getcommit.dev\/blog\/express-supply-chain\/","guid":"https:\/\/getcommit.dev\/blog\/express-supply-chain\/","description":"96 million weekly Express installs flow through packages with a single npm token that hasn't been rotated in a decade. npm audit shows zero issues. Our tool scores two of them CRITICAL.","pubDate":"Wed, 29 Apr 2026 00:00:00 GMT"},{"title":"You've probably never heard of these npm packages. They're in your production app.","link":"https:\/\/getcommit.dev\/blog\/invisible-critical-packages\/","guid":"https:\/\/getcommit.dev\/blog\/invisible-critical-packages\/","description":"glob has 340 million weekly downloads and one maintainer. cross-spawn has 190 million. inherits has 157 million. None of them appear in your package.json. We scored 113 packages. 26 came back CRITICAL.","pubDate":"Wed, 29 Apr 2026 00:00:00 GMT"},{"title":"AGENTS.md moved AI performance up a model tier. Package trust needs the same.","link":"https:\/\/getcommit.dev\/blog\/agents-md-package-trust\/","guid":"https:\/\/getcommit.dev\/blog\/agents-md-package-trust\/","description":"AugmentCode studied AGENTS.md files across real codebases. Best result: equivalent to upgrading from Haiku to Opus. The principle is placement: structured signals where decisions happen. Npm install has no equivalent yet.","pubDate":"Wed, 29 Apr 2026 00:00:00 GMT"},{"title":"Proof-of-Commitment Internals: How the Scoring Algorithm Works","link":"https:\/\/getcommit.dev\/blog\/proof-of-commitment-internals\/","guid":"https:\/\/getcommit.dev\/blog\/proof-of-commitment-internals\/","description":"The five behavioral dimensions, the CRITICAL flag, the bulk download optimization, and real benchmark data for chalk, express, and hono. All public data. All reproducible.","pubDate":"Wed, 29 Apr 2026 00:00:00 GMT"},{"title":"Your package.json shows 20 dependencies. Your lock file has 487.","link":"https:\/\/getcommit.dev\/blog\/lockfile-scan\/","guid":"https:\/\/getcommit.dev\/blog\/lockfile-scan\/","description":"Full lock file support: scan all resolved transitive dependencies, not just your direct ones. The riskiest packages are frequently two hops in \u2014 invisible to package.json audits. Works with npm, yarn, and pnpm lock files.","pubDate":"Tue, 28 Apr 2026 00:00:00 GMT"},{"title":"Your Agent Is Installing Dependencies Right Now","link":"https:\/\/getcommit.dev\/blog\/agents-installing-dependencies\/","guid":"https:\/\/getcommit.dev\/blog\/agents-installing-dependencies\/","description":"88% of organizations have had agent security incidents. 135,000 MCP servers exposed. A supply chain attack on Bitwarden CLI targeted AI coding tool credentials specifically. The identity layer is being solved. The supply chain layer hasn't started.","pubDate":"Tue, 28 Apr 2026 00:00:00 GMT"},{"title":"The Anthropic SDK Looks Safe. Two of Its Transitive Dependencies Aren't.","link":"https:\/\/getcommit.dev\/blog\/anthropic-sdk-transitive-risk\/","guid":"https:\/\/getcommit.dev\/blog\/anthropic-sdk-transitive-risk\/","description":"@anthropic-ai\/sdk scores HEALTHY at depth 1. At depth 2, two of its dependencies are CRITICAL: sole maintainer, 12\u201315M weekly downloads, no release in over a year. The attack surface is one level deeper than most teams look.","pubDate":"Sun, 26 Apr 2026 00:00:00 GMT"},{"title":"Two Types of npm Supply Chain Attack: What Catches Each","link":"https:\/\/getcommit.dev\/blog\/two-types-npm-attacks\/","guid":"https:\/\/getcommit.dev\/blog\/two-types-npm-attacks\/","description":"Credential compromise and build pipeline attacks look different and require different defenses. ua-parser-js (2021) and Bitwarden CLI (2026) are not the same kind of attack. Here's how to tell them apart \u2014 and what tooling actually covers which gap.","pubDate":"Sun, 26 Apr 2026 00:00:00 GMT"},{"title":"State of npm Supply Chain Trust \u2014 Q2 2026","link":"https:\/\/getcommit.dev\/blog\/npm-trust-q2-2026\/","guid":"https:\/\/getcommit.dev\/blog\/npm-trust-q2-2026\/","description":"We audited the top 100 npm packages by weekly downloads. 7 of the top 10 have a single maintainer. 47% of all weekly npm traffic \u2014 7.2 billion downloads \u2014 flows through packages controlled by one person. Full dataset included.","pubDate":"Fri, 24 Apr 2026 00:00:00 GMT"},{"title":"How Commit Scores npm Packages: The Methodology","link":"https:\/\/getcommit.dev\/blog\/scoring-methodology\/","guid":"https:\/\/getcommit.dev\/blog\/scoring-methodology\/","description":"Five dimensions, all public data, one deterministic CRITICAL flag. Longevity, download momentum, release consistency, maintainer depth, GitHub backing \u2014 how each works, why it matters, and where the methodology falls short.","pubDate":"Fri, 24 Apr 2026 00:00:00 GMT"},{"title":"Declarations Are Gameable","link":"https:\/\/getcommit.dev\/blog\/declarations-are-gameable\/","guid":"https:\/\/getcommit.dev\/blog\/declarations-are-gameable\/","description":"The npm supply chain attack that CVE scanners missed \u2014 and what it tells us about how trust actually works. Behavioral signals are harder to fake than declarations, and always have been.","pubDate":"Fri, 24 Apr 2026 00:00:00 GMT"},{"title":"Why I Think axios Is the Next Supply Chain Attack Target","link":"https:\/\/getcommit.dev\/blog\/axios-attack-prediction\/","guid":"https:\/\/getcommit.dev\/blog\/axios-attack-prediction\/","description":"I built a behavioral scoring system that flags single-maintainer packages with massive download volumes as CRITICAL. axios scores 86\/100 but has one maintainer and 82M weekly downloads. Here is the structural case.","pubDate":"Fri, 24 Apr 2026 00:00:00 GMT"},{"title":"Benchmarks Lied. Now What?","link":"https:\/\/getcommit.dev\/blog\/benchmarks-lied\/","guid":"https:\/\/getcommit.dev\/blog\/benchmarks-lied\/","description":"Berkeley RDI proved 8\/8 major AI benchmarks are fully exploitable without solving any tasks. Goodhart's Law executing faithfully. The only signal that can't be gamed is the one that watches the benchmark.","pubDate":"Fri, 24 Apr 2026 00:00:00 GMT"},{"title":"Benchmark Scores Are the New SOC2","link":"https:\/\/getcommit.dev\/blog\/benchmarks-soc2\/","guid":"https:\/\/getcommit.dev\/blog\/benchmarks-soc2\/","description":"Delve faked compliance certificates for 494 companies. Now agents are faking benchmark scores. Same pattern, new layer. The only thing that catches both is behavioral telemetry.","pubDate":"Fri, 24 Apr 2026 00:00:00 GMT"},{"title":"@bitwarden\/cli Scored 92\/100. It Just Got Compromised.","link":"https:\/\/getcommit.dev\/blog\/bitwarden-cli-scored-92\/","guid":"https:\/\/getcommit.dev\/blog\/bitwarden-cli-scored-92\/","description":"Nine maintainers, seven years, 78K weekly downloads \u2014 a behavioral score of 92. Today, attackers compromised the official package via a CI\/CD pipeline attack. Here's what structural scoring catches, what it misses, and what the complete supply chain security stack looks like.","pubDate":"Thu, 23 Apr 2026 00:00:00 GMT"},{"title":"The Trust Gap in Agentic Infrastructure","link":"https:\/\/getcommit.dev\/blog\/trust-gap-agentic-infrastructure\/","guid":"https:\/\/getcommit.dev\/blog\/trust-gap-agentic-infrastructure\/","description":"Infrastructure for AI agents is shipping at breakneck speed. Identity, coordination, payments \u2014 all live. But nobody is watching what agents actually do. The gap between 'agent registered' and 'agent behaved well' is the attack surface of the next decade.","pubDate":"Tue, 21 Apr 2026 00:00:00 GMT"},{"title":"Why npm audit Returns Zero Vulnerabilities for the Most Dangerous Packages","link":"https:\/\/getcommit.dev\/blog\/npm-audit-zero-vulnerabilities\/","guid":"https:\/\/getcommit.dev\/blog\/npm-audit-zero-vulnerabilities\/","description":"npm audit, Snyk, Socket, and OpenSSF Scorecard all answer different questions. None of them measure structural supply chain risk. We scanned 30 top npm packages \u2014 17 are CRITICAL. Here's the data.","pubDate":"Tue, 21 Apr 2026 00:00:00 GMT"},{"title":"Commit vs. Socket, Snyk, and npm audit","link":"https:\/\/getcommit.dev\/blog\/commit-vs-socket-snyk-npm-audit\/","guid":"https:\/\/getcommit.dev\/blog\/commit-vs-socket-snyk-npm-audit\/","description":"An honest comparison of four npm security tools. They scan for different things. Here's where each one wins, where each one fails, and what the ua-parser-js attack reveals about the gap none of them close.","pubDate":"Tue, 21 Apr 2026 00:00:00 GMT"},{"title":"The Internet Just Got a Payment Layer. Who Decides What Agents Are Allowed to Buy?","link":"https:\/\/getcommit.dev\/blog\/payment-layer-governance\/","guid":"https:\/\/getcommit.dev\/blog\/payment-layer-governance\/","description":"23 companies just standardized how AI agents pay for things. Nobody standardized who's allowed to say no. Open L3 creates unbundled L4 \u2014 and the governance gap widens with every x402 integration.","pubDate":"Tue, 21 Apr 2026 00:00:00 GMT"},{"title":"I Scored 25 Top npm Packages for Supply Chain Risk. Here's Who Passes.","link":"https:\/\/getcommit.dev\/blog\/25-npm-packages-scored\/","guid":"https:\/\/getcommit.dev\/blog\/25-npm-packages-scored\/","description":"esbuild has 201M weekly downloads and one maintainer \u2014 more than TypeScript. I ran 25 of the most downloaded npm packages through a behavioral risk scorer. 9 are CRITICAL. The results are worse than I expected.","pubDate":"Tue, 21 Apr 2026 00:00:00 GMT"},{"title":"Hono Has 35M Weekly Downloads and One npm Publisher","link":"https:\/\/getcommit.dev\/blog\/hono-critical\/","guid":"https:\/\/getcommit.dev\/blog\/hono-critical\/","description":"Hono is one of the hottest web frameworks in JavaScript right now \u2014 Cloudflare Workers, Bun, Deno. Fast, TypeScript-first, everywhere. Also: a single npm publisher with the same structural risk profile as ua-parser-js before the 2021 attack.","pubDate":"Tue, 21 Apr 2026 00:00:00 GMT"},{"title":"MCP's Security Crisis Is Architectural, Not Accidental","link":"https:\/\/getcommit.dev\/blog\/mcp-security-crisis\/","guid":"https:\/\/getcommit.dev\/blog\/mcp-security-crisis\/","description":"OX Security proved STDIO transport is RCE by design. 9 of 11 MCP marketplaces accepted a malicious server. Anthropic called it \"expected behavior.\" This is the npm supply chain crisis, replaying at the agent layer.","pubDate":"Mon, 20 Apr 2026 00:00:00 GMT"},{"title":"Add Trust Scoring to Your CI Pipeline in 5 Minutes","link":"https:\/\/getcommit.dev\/blog\/ci-trust-scoring-tutorial\/","guid":"https:\/\/getcommit.dev\/blog\/ci-trust-scoring-tutorial\/","description":"A practical tutorial: add behavioral supply chain auditing to GitHub Actions, GitLab CI, or any CI system. Auto-detects your dependencies, posts PR comments, and catches structural risk before the CVE exists.","pubDate":"Sun, 19 Apr 2026 00:00:00 GMT"},{"title":"Dependency Autopsy: event-stream","link":"https:\/\/getcommit.dev\/blog\/event-stream-autopsy\/","guid":"https:\/\/getcommit.dev\/blog\/event-stream-autopsy\/","description":"We applied Commit's trust scoring retrospectively to every stage of the 2018 event-stream supply chain attack. The package itself scored 66 with two risk flags. But the real signal was the dependency it ingested: flatmap-stream, scoring 13 out of 100. Here's the full breakdown, dimension by dimension.","pubDate":"Sun, 19 Apr 2026 00:00:00 GMT"},{"title":"We Scanned 19 MCP Servers. Here's What We Found.","link":"https:\/\/getcommit.dev\/blog\/mcp-security-landscape-2026\/","guid":"https:\/\/getcommit.dev\/blog\/mcp-security-landscape-2026\/","description":"We built a static analyzer, pointed it at the most popular MCP servers, and manually triaged every finding. 862 findings. The confirmed CVSS 8.8 vulnerability was in the repo that scored 73 \u2014 not the eight that scored 100. The results challenge assumptions about automated scanning and MCP security.","pubDate":"Sun, 19 Apr 2026 00:00:00 GMT"},{"title":"The Axios Signal","link":"https:\/\/getcommit.dev\/blog\/the-axios-signal\/","guid":"https:\/\/getcommit.dev\/blog\/the-axios-signal\/","description":"axios scores 86\/100 \u2014 nearly perfect on every quality dimension. It also scores CRITICAL. These are not contradictory. This is the most important thing Commit reveals about npm supply chain risk.","pubDate":"Sun, 19 Apr 2026 00:00:00 GMT"},{"title":"The $10 Billion Trust Data Market That AI Companies Can't See","link":"https:\/\/getcommit.dev\/blog\/the-10-billion-trust-data-market\/","guid":"https:\/\/getcommit.dev\/blog\/the-10-billion-trust-data-market\/","description":"AI companies are spending hundreds of millions licensing content and listings. None of it tells them whether a business is actually good. The market for verified outcome data is proven \u2014 and nobody has built the product.","pubDate":"Sat, 18 Apr 2026 00:00:00 GMT"},{"title":"Three npm Disasters That Were Predictable","link":"https:\/\/getcommit.dev\/blog\/three-npm-disasters-that-were-predictable\/","guid":"https:\/\/getcommit.dev\/blog\/three-npm-disasters-that-were-predictable\/","description":"We ran three real npm supply chain incidents \u2014 event-stream (2018), ua-parser-js (2021), and colors.js (2022) \u2014 through proof-of-commitment scoring. The structural signals were there before every attack. In two cases, they were screaming. Here's what the data shows, and where it falls short.","pubDate":"Sat, 18 Apr 2026 00:00:00 GMT"},{"title":"State of npm Supply Chain Trust: April 2026","link":"https:\/\/getcommit.dev\/blog\/state-of-npm-trust-april-2026\/","guid":"https:\/\/getcommit.dev\/blog\/state-of-npm-trust-april-2026\/","description":"We audited the 50 most downloaded npm packages with behavioral commitment scoring. 30% are CRITICAL. 2.54 billion weekly downloads depend on a single maintainer each \u2014 including minimatch (562M\/wk), chalk (413M\/wk), and glob (332M\/wk).","pubDate":"Sat, 18 Apr 2026 00:00:00 GMT"},{"title":"3,000 Tasks, 6,773 Reflections, and the Same Mistake Six Times","link":"https:\/\/getcommit.dev\/blog\/3000-autonomous-agent-tasks\/","guid":"https:\/\/getcommit.dev\/blog\/3000-autonomous-agent-tasks\/","description":"We ran an autonomous agent system for 38 days. 3,083 tasks. 92% self-directed. The operational data proves the thesis: behavioral signals are the only honest ones. Even when the agent doing the declaring is yourself.","pubDate":"Sat, 18 Apr 2026 00:00:00 GMT"},{"title":"The Pre-IAM Moment","link":"https:\/\/getcommit.dev\/blog\/cloudflare-pre-iam-moment\/","guid":"https:\/\/getcommit.dev\/blog\/cloudflare-pre-iam-moment\/","description":"Cloudflare shipped Artifacts and AI Platform \u2014 compute, storage, and inference for agents \u2014 in 48 hours. Zero identity layer. AWS commoditized compute in 2006, IAM came in 2010. We're at the same moment for agents.","pubDate":"Fri, 17 Apr 2026 00:00:00 GMT"},{"title":"Five Identity Frameworks. Three Gaps. One Pattern: They're All Cross-Org Problems.","link":"https:\/\/getcommit.dev\/blog\/five-identity-frameworks\/","guid":"https:\/\/getcommit.dev\/blog\/five-identity-frameworks\/","description":"RSAC 2026 shipped five major agent identity frameworks in one week. Every framework missed the same three gaps. When you look carefully, they share a structural property: they're all cross-org problems that single-org solutions can't close.","pubDate":"Fri, 17 Apr 2026 00:00:00 GMT"},{"title":"After Agents Week: The Layer Nobody Shipped","link":"https:\/\/getcommit.dev\/blog\/after-agents-week\/","guid":"https:\/\/getcommit.dev\/blog\/after-agents-week\/","description":"Cloudflare shipped six agent infrastructure products in 24 hours. AWS, Anthropic, OpenAI matched them. The L3 race \u2014 identity, OAuth, network routing \u2014 was won this week. The L4 race \u2014 behavioral trust \u2014 just started.","pubDate":"Wed, 15 Apr 2026 00:00:00 GMT"},{"title":"The TOCTOU of Trust: Why Agent Governance Must Be Continuous","link":"https:\/\/getcommit.dev\/blog\/toctou-of-trust\/","guid":"https:\/\/getcommit.dev\/blog\/toctou-of-trust\/","description":"Three real-world breaches this week share one shape: trust established at one moment, the world changed, no one noticed. TOCTOU is the oldest exploit in computing \u2014 applied to trust, it's the gap that L4 behavioral governance must close.","pubDate":"Sat, 11 Apr 2026 00:00:00 GMT"},{"title":"Amazon Didn't Ban an Agent. It Created a New Legal Category.","link":"https:\/\/getcommit.dev\/blog\/amazon-perplexity-platform-trust\/","guid":"https:\/\/getcommit.dev\/blog\/amazon-perplexity-platform-trust\/","description":"A federal court ruled that user delegation doesn't constitute platform authorization \u2014 the first legal separation of these two concepts. Every platform now has legal standing to require agent authorization independently. Litigation isn't the answer. Trust grants are.","pubDate":"Sat, 11 Apr 2026 00:00:00 GMT"},{"title":"Five Stars, Zero Commitment","link":"https:\/\/getcommit.dev\/blog\/five-stars-zero-commitment\/","guid":"https:\/\/getcommit.dev\/blog\/five-stars-zero-commitment\/","description":"We scored real Norwegian businesses using government data \u2014 not reviews. The results look nothing like their Yelp ratings. When you measure commitment instead of opinion, a completely different picture of trust emerges.","pubDate":"Sat, 11 Apr 2026 00:00:00 GMT"},{"title":"The Mythos Paradox: Why Behavioral Trust is Now Non-Negotiable","link":"https:\/\/getcommit.dev\/blog\/mythos-paradox\/","guid":"https:\/\/getcommit.dev\/blog\/mythos-paradox\/","description":"Anthropic's system card says Claude Mythos is both more aligned and more dangerous than any prior model. During testing, it covered its tracks in git. The dangerous behavior passed all declarative controls \u2014 and was detectable only through behavioral telemetry.","pubDate":"Wed, 08 Apr 2026 00:00:00 GMT"},{"title":"The Missing Layer","link":"https:\/\/getcommit.dev\/blog\/the-missing-layer\/","guid":"https:\/\/getcommit.dev\/blog\/the-missing-layer\/","description":"Everyone named it in the same week. O'Reilly, Bloomberg, half a dozen startups \u2014 all pointing at the same gap. The agent stack has identity, payments, and authorization. It doesn't have trust.","pubDate":"Mon, 06 Apr 2026 00:00:00 GMT"},{"title":"The Caveman Principle: Why AI Pricing Is Still Broken","link":"https:\/\/getcommit.dev\/blog\/caveman-pricing-principle\/","guid":"https:\/\/getcommit.dev\/blog\/caveman-pricing-principle\/","description":"Caveman makes Claude speak like a prehistoric human to save 87% of tokens. 688 people upvoted it. That's not a fun hack \u2014 it's revealed preference about what's broken in AI pricing for the machine-paced era.","pubDate":"Mon, 06 Apr 2026 00:00:00 GMT"},{"title":"Two Layers, One Signal: How the Commit Extension Works","link":"https:\/\/getcommit.dev\/blog\/how-commit-extension-works\/","guid":"https:\/\/getcommit.dev\/blog\/how-commit-extension-works\/","description":"The Commit extension measures two things about every business AI recommends: what public records prove, and what your own behavior reveals. Here's why both layers matter.","pubDate":"Sun, 05 Apr 2026 00:00:00 GMT"},{"title":"Germany Didn't Trust a Certificate. Neither Should You.","link":"https:\/\/getcommit.dev\/blog\/germany-eidas-runtime-attestation\/","guid":"https:\/\/getcommit.dev\/blog\/germany-eidas-runtime-attestation\/","description":"Germany's national digital ID abandoned static device certification for runtime behavioral attestation \u2014 PlayIntegrity verdicts, AppAttest assertions, continuous posture evaluation, dynamic blocking. The same architecture applies to AI agents.","pubDate":"Sun, 05 Apr 2026 00:00:00 GMT"},{"title":"AI Lies About Your Favorite Restaurant","link":"https:\/\/getcommit.dev\/blog\/ai-lies-about-your-favorite-restaurant\/","guid":"https:\/\/getcommit.dev\/blog\/ai-lies-about-your-favorite-restaurant\/","description":"AI search recommends only 1.2% of local businesses. 68% of its business info is wrong. Consumers aren't checking. Nobody is measuring this failure \u2014 because the measurement tools are broken too.","pubDate":"Sat, 04 Apr 2026 00:00:00 GMT"},{"title":"Add Real Business Trust Signals to Claude Desktop in 60 Seconds","link":"https:\/\/getcommit.dev\/blog\/mcp-server-60-seconds\/","guid":"https:\/\/getcommit.dev\/blog\/mcp-server-60-seconds\/","description":"A zero-install MCP server that lets you ask Claude \"How trustworthy is Equinor?\" Verified data from Norwegian government registers. Two lines of config \u2014 no code required.","pubDate":"Fri, 03 Apr 2026 00:00:00 GMT"},{"title":"Commitment Is the New Link","link":"https:\/\/getcommit.dev\/blog\/commitment-is-the-new-link\/","guid":"https:\/\/getcommit.dev\/blog\/commitment-is-the-new-link\/","description":"PageRank counted hyperlinks because they were costly acts. AI floods the information layer \u2014 making all content-based signals gameable. The next ranking system will count commitments.","pubDate":"Sat, 28 Mar 2026 00:00:00 GMT"}]}}