This week's articles
GitHub Actions could be so much better
#build, #ci/cd
GitHub Actions is a regular source of profound frustration for the author of this post in their development processes. This post lists some of those frustrations, and how they think GitHub could improve on them (or even fix them outright).
Surprise: When Dependabot Contributes Malicious Code
#attack, #ci/cd
In July 2023, malicious commits were detected on GitHub, disguised as contributions by Dependabot. Threat actors fabricated these to steal users' GitHub personal access tokens and insert malicious code, which exfiltrated project secrets to a server and modified JavaScript files with password-stealer malware, affecting end-users.
MITRE Security Automation Framework
#strategy, #supply-chain
MITRE SAF supports security processes at all stages of the software lifecycle, from planning secure system design to analyzing operational security data.
|