T
traeai
Sign in

概念

什么是 OIDC

也叫:OpenID-Connect

用于身份验证和授权的开放标准。

为什么现在值得关注?

最近变化

2026-06-08 · 73个微软开源包被植入恶意代码,触发凭证窃取攻击。

OIDC 被反复提及时,通常意味着它正在影响产品路线、开发者工作流或 AI 产业判断。这个页面把分散材料合并成一个可持续更新的观察入口。

📰 OIDC 最新动态

已收录 8 篇与「OIDC」相关的 AI 资讯和分析。

Postmortem: TanStack npm supply-chain compromise

Postmortem: TanStack npm supply-chain compromise

Hacker News Best2746 字 (约 11 分钟)
95

TanStack suffered an npm supply-chain compromise on May 11, 2026, where attackers published 84 malicious versions across 42 packages using GitHub Actions cache poisoning and OIDC token extraction without stealing npm tokens directly.

入选理由:Attackers exploited pull_request_target and GitHub Actions cache poisoning to publish 84 malicious versions in 6 minutes.

FeaturedArticle#Security#Supply Chain#npm#GitHub Actions#TanStack英文
npm 生态遭大范围投毒:TanStack、Mistral AI、UiPath 等受波及,可窃取云密钥与 GitHub 令牌

A large-scale supply chain attack hit the npm ecosystem, affecting over 160 packages including TanStack, Mistral AI, and UiPath; attackers used GitHub Actions vulnerabilities and OIDC tokens to publish malicious code under trusted identities.

入选理由:攻击者利用 GitHub Actions 的 pull_request_target 漏洞与跨 fork 缓存投毒,绕过双重验证完成恶意发布。

FeaturedArticle#npm#supply chain attack#GitHub Actions#security vulnerability#open source ecosystem中文
For the 2nd time in weeks, Microsoft packages laced with credential stealer

微软开源包遭恶意代码感染,触发凭证窃取攻击,影响73个包,攻击者利用AI工具传播。

入选理由:73个微软开源包被植入恶意代码,触发凭证窃取攻击。

FeaturedArticle#微软#供应链攻击#AI工具#安全漏洞英文
Vercel News 图标

Signed URLs are now available for Vercel Blob

Vercel News375 字 (约 2 分钟)
82

Vercel Blob now supports generating time-bound signed URLs, enabling direct browser uploads, downloads, inspections, or deletions of specific objects with high security and no exposure of long-lived storage tokens.

入选理由:支持 PUT、GET、HEAD 和 DELETE 四种操作的签名 URL,有效期最长 7 天。

FeaturedArticle#Vercel#Blob#Signed URLs#OIDC#File Storage英文
Vercel Blob now supports OIDC authentication

Vercel Blob now supports OIDC authentication

Vercel News634 字 (约 3 分钟)
75

Vercel Blob now supports OIDC authentication and is the default setting when connecting new projects, enhancing security and integration flexibility.

入选理由:Vercel Blob 从 2026 年 6 月 1 日起支持 OIDC 认证,作为新项目连接的默认设置。

FeaturedArticle#Vercel#OIDC#Blob#Authentication#Cloud Storage英文
OpenShell v0.0.41

🧩 agent-driven policy management
🎚️ sandbox resource flags in the CLI
🔒 custom...

NVIDIA OpenShell v0.0.41 Release Notes

NVIDIA AI(@NVIDIAAI)111 字 (约 1 分钟)
75

NVIDIA OpenShell v0.0.41 introduces agent-driven policy management, CLI sandbox resource flags, and custom CA support for OIDC TLS.

入选理由:支持 agent-driven policy management,提升自动化控制能力。

FeaturedTweet#NVIDIA#OpenShell#CLI#Security#Sandbox中英混合
Give Your Agent a Computer — Nico Albanese, Vercel

Give Your Agent a Computer — Nico Albanese, Vercel

AI Engineer14368 字 (约 58 分钟)
55

Vercel CLI provides convenient deployment and environment variable management features to help developers quickly set up and validate projects.

入选理由:使用 Vercel CLI 可以简化项目的部署流程。

FeaturedVideo#Vercel#CLI#AI英文
OpenShell v0.0.43

🛠️ bidirectional TTY streaming
🔒 OIDC auth in the TUI
🧩 HTTPS and mTLS decoupl...

OpenShell v0.0.43

NVIDIA AI(@NVIDIAAI)168 字 (约 1 分钟)
50

OpenShell v0.0.43 release adds 6 security and feature improvements including bidirectional TTY streaming, OIDC auth, HTTPS/mTLS decoupling, TOML gateway config, ext4 disk boot for sandboxes, and DNS removal.

入选理由:双向TTY流和TUI内置OIDC认证增强交互与安全性

FeaturedTweet#OpenShell#NVIDIA#Sandbox Security#OIDC Authentication#TTY Streaming英文

与「OIDC」经常一起出现的 AI 术语。

💡 想追踪「OIDC」的长期趋势?去 实体雷达 · OIDC 查看详细分析和跨材料问答。

AI may generate inaccurate information. Please verify important content.