ci-cd 17
- We hardened zizmor's GitHub Actions static analyzer
- Shai-Hulud Is Back, and This Time It Ate the Whole Ecosystem
- Reduce CVE noise with OpenVEX assessments in Datadog
- durabletask: TeamPCP's Latest PyPi Compromise
- Living Off the Pipeline: Defending Against CI/CD Subversion
- The Convergence of Cloud Secrets & AI Risk
- Shai-Hulud Goes Open Source
- Composer vulnerability leaks GitHub tokens, threatens PHP supply chain
- Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised
- Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years
- From Code to Pipeline: Wiz Code Now Secures Your Build Environment
- Spotting CI/CD misconfigurations before the bots do: Securing GitHub Actions with Datadog IaC Security
- The case for dependency cooldowns in a post-axios world
- Primer on GitHub Actions Security - Threat Model, Attacks and Defenses (Part 1/2)
- CI/CD security: How to secure your GitHub ecosystem
- CI/CD security: threat modeling using a MITRE-style threat matrix
- Six Accounts, One Actor: Inside the prt-scan Supply Chain Campaign