#provenance-and-oidc

[ follow ]
Information security
fromDevOps.com
2 days ago

Widespread Mini Shai-Hulud Campaign Is a Matter of Trust - DevOps.com

Shai-Hulud attacks evolve into supply-chain playbooks that abuse trusted CI/CD publishing paths and OIDC tokens to deliver malicious packages with valid provenance.
[ Load more ]