tag
CI/CD
7 posts
- Packagist Urges Immediate Composer Update After GitHub Actions Token Leak
- Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft
- Malicious Ruby Gems and Go Modules Impersonate Developer Tools to Steal Secrets and Poison CI
- CI/CD pipeline abuse: the problem no one is watching
- Supply chain attacks hit Checkmarx and Bitwarden developer tools
- Axios Supply Chain Attack Reaches OpenAI macOS Signing Pipeline, Forces Certificate Rotation
- TeamPCP Is Systematically Targeting Security Tools Across the OSS Ecosystem