the.bay.news

Valid provenance is not valid code: a supply-chain worm shipped with a valid SLSA attestation

DEV Community
Valid provenance is not valid code: a supply-chain worm shipped with a valid SLSA attestation
The Mini Shai-Hulud worm didn't steal a publish token — it abused the CI environment itself, and its packages passed SLSA provenance validation. What attestations prove, what they don't, and the two layers still missing.

0 comments

Sign in to join the discussion — your thebay.events account works here.

No comments yet.