#ci-cd
Wiki 6
- CI Runner Token Extraction Code on a CI runner reads the runner-process memory to extract OIDC tokens for direct registry use
- GitHub Actions Cache Poisoning Attacker-controlled job writes cache entries that production workflows later restore
- Open Source Security at Astral Astral's full supply chain security posture; CI/CD lockdown, Trusted Publishing, Sigstore, cooldowns
- Pwn Request Pattern GitHub's `pull_request_target` running fork-controlled code in the base repo's permission context
- Supply Chain Security Protecting code-to-artifact chain: CI/CD, dependencies, registries, releases, defense patterns
- TanStack npm Supply Chain Compromise — Postmortem How three known vulnerabilities chained into 84 malicious @tanstack/* npm publishes, and what stops the same chain