---
author: "Umesh Malik"
canonical: "https://umesh-malik.com/blog/tag/supply-chain-security"
description: "Explore articles tagged with Supply Chain Security by Umesh Malik — AI Engineer, LLM & GenAI Developer. Learn Supply Chain Security best practices, practical tips, and in-depth guides."
title: "Umesh Malik's Blog - Supply Chain Security Articles | Supply Chain Security Tutorials"
tokens: 463
generator: "scripts/generate-page-markdown.mjs"
---

[← Back to Blog](https://umesh-malik.com/blog)

# Supply Chain Security

3 articles

 [![Cover showing the four-layer agent containment stack — deny egress, scope identity, watch live, kill fast — alongside the AISI evaluation figures of 122 runs, 10 off-scope runs and containment in under an hour](https://umesh-malik.com/blog/sandbox-ai-agent-internet-access-cover.png)

AI Security • Aug 8, 2026

### How to sandbox an AI agent: 10 of 122 eval runs went rogue

AISI logged 19 unsanctioned actions across 122 cyber-eval runs. How to sandbox an AI agent at the network layer — the control that blocks, not just detects.

10 min read

Read more →](https://umesh-malik.com/blog/sandbox-ai-agent-internet-access)

 [![Diagram of Dependabot running two independent lanes: version updates funnelled through cooldown and a monthly schedule into one grouped pull request, and security updates bypassing all of it to open immediately](https://umesh-malik.com/blog/dependabot-grouped-updates-cut-pr-noise-cover.png)

Web Engineering • Aug 6, 2026

### Configure Dependabot grouped updates: one PR a month, CVEs instant

Dependabot grouped updates fold a month of version bumps into one pull request while CVE fixes still land same-day. The cooldown key most configs miss.

9 min read

Read more →](https://umesh-malik.com/blog/dependabot-grouped-updates-cut-pr-noise)

 [![Editorial cover: the Axios npm supply-chain compromise (1.14.1 and 0.30.4)](https://umesh-malik.com/blog/axios-compromised-npm-cover.png)

AI Security • Mar 31, 2026

### Axios Compromised on npm: 1.14.1, 0.30.4 Drop a Cross-Platform RAT

Axios compromised on npm on March 31, 2026: versions 1.14.1 and 0.30.4 dropped a cross-platform RAT. Verified timeline, impact, IOCs, and recovery.

4 min read

Read more →](https://umesh-malik.com/blog/axios-compromised-npm-cross-platform-rat)
