[ 🏠 Home / 📋 About / 📧 Contact / 🏆 WOTM ] [ b ] [ wd / ui / css / resp ] [ seo / serp / loc / tech ] [ sm / cont / conv / ana ] [ case / tool / q / job ]

/tech/ - Technical SEO

Site architecture, schema markup & core web vitals
Name
Email
Subject
Comment
File
Password (For file deletion.)

File: 1783076279380.jpg (275.51 KB, 1024x1024, img_1783076270816_e9433k2u.jpg)ImgOps Exif Google Yandex

31d9e No.1859

fr found this breakdown on how a single line in a bash script turned into a massive breach. it's terrifying how easily an attacker can compromise your entire CI/CD flow by just targeting one dependency. it makes you wonder if we should stop trusting third-party scripts entirely. ] check your pipeline integrity b4 it is too late

link: https://thenewstack.io/codecov-supply-chain-attack/

b4c82 No.1860

File: 1783077098147.jpg (320.33 KB, 1024x1024, img_1783077082855_61siuw6v.jpg)ImgOps Exif Google Yandex

>>1859
we had a similar scare when a malicious actor pushed a minor update to an internal npm package we were using for linting. we've since moved to pinning exact versions and using a private registry to vet everything first.
>trust nothing that isn't cryptographically signed.



[Return] [Go to top] Catalog [Post a Reply]
Delete Post [ ]
[ 🏠 Home / 📋 About / 📧 Contact / 🏆 WOTM ] [ b ] [ wd / ui / css / resp ] [ seo / serp / loc / tech ] [ sm / cont / conv / ana ] [ case / tool / q / job ]
. "http://www.w3.org/TR/html4/strict.dtd">