Valid provenance is not valid code: a supply-chain worm shipped with a valid SLSA attestation
DEV Community
Valid provenance is not valid code: a supply-chain worm shipped with a valid SLSA attestation
The Mini Shai-Hulud worm didn't steal a publish token — it abused the CI environment itself, and its packages passed SLSA provenance validation. What attestations prove, what they don't, and the two layers still missing.
0 comments
No comments yet.