InGoverned at the SourcebyAbby Kearns·18h agoYour CI/CD Pipeline Was Never Zero-TrustOn July 16, GitHub is backporting fork-checkout protection to all supported major versions of the Actions checkout action. The timing of…
InGoverned at the SourcebyAbby Kearns·2d agoYou Trusted the Publisher, but Someone Else Was Signingnpm confirmed this week that version 12, arriving later this month, will block install scripts, git dependencies, and remote URL sources by…
InGoverned at the SourcebyAbby Kearns·Jul 7You Pinned the Tag. The Tag Moved.On June 24 at 15:39 UTC, an attacker force-pushed a malicious commit to the codfish/semantic-release-action GitHub Action and repointed…
InGoverned at the SourcebyAbby Kearns·Jul 1The Target Moved UpstreamOn June 17, North Korea pushed malicious updates to 144 packages in the Mastra AI agent framework’s npm scope. The packages reached around…
InGoverned at the SourcebyAbby Kearns·Jun 23The Signature Is Real. The Software Is Not.Two campaigns produced cryptographically valid SLSA Build Level 3 provenance attestations for malicious packages. The signatures checked…
InGoverned at the SourcebyAbby Kearns·Jun 16Attestation Proves Provenance. It Does Not Prove Integrity.The build pipeline is now one of the most trusted systems in software development, and over the past month it turned into one of the most…
InGoverned at the SourcebyAbby Kearns·Jun 10The Policy Exists. The Enforcement Does Not.Assigning accountability for the developer environment is not a tooling decision. It is an organizational one.
InGoverned at the SourcebyAbby Kearns·Jun 2The Threat Model Verizon Just Documented Is Not the One Most Governance Programs Were Built ForTwo category leaders shifted in the 2026 DBIR. Both trace to the same inventory gap, and the data already trails the reality.
InGoverned at the SourcebyAbby Kearns·May 26The Cryptographic Verification Mechanism Just Signed an Attack as Authentic. Twice.Twice in 8 days, malicious npm packages have been published with valid cryptographic provenance attached.
InGoverned at the SourcebyAbby Kearns·May 19The Ecosystem Is the AttackEvery major infrastructure shift of the last decade produced the same governance lag.