JFrog & GitHub: Unifying the Software Supply Chain, One Step at a Time… and Our 2025 GitHub Technology Partner Award
October 28, 2025 | 6 min read
November 4, 2025
12 min read
The JFrog Security Research team recently discovered and disclosed CVE-2025-11953 - a critical (CVSS 9.8) security vulnerability affecting the extremely popular @react-native-community/cli NPM package that has approximately 2M weekly downloads. The vulnerability allows remote unauthenticated attackers to easily trigger arbitrary OS command execution on the machine running react-native-community/cli’s development server, posing a significant risk to…
October 28, 2025 | 6 min read
October 21, 2025 | 10 min read
October 16, 2025 | 7 min read
October 15, 2025 | 5 min read
September 19, 2025 | 4 min read
October 1, 2025 | 4 min read
September 16, 2025 | 11 min read
September 11, 2025 | 5 min read
September 10, 2025 | 4 min read
September 17, 2025 | 13 min read