SLSA signatures did not save you from Shai Hulud
Over 160 npm packages were backdoored with valid SLSA Build Level 3 attestations. The trust model for GitHub Actions is broken -- here is what to fix.
3 articles tagged #ci-cd
Over 160 npm packages were backdoored with valid SLSA Build Level 3 attestations. The trust model for GitHub Actions is broken -- here is what to fix.
Axe flags which WCAG criterion failed. @holmdigital/engine maps that to the law you broke, the enforcing authority, and 17 countries in scope including the EAA.
The shift to internal developer platforms and AIOps is real. The reason DevOps engineers are angry about it is worth looking at honestly.