Cloning a Repo Is Code Execution [Part 1] — Anatomy of a Repo-Borne Supply-Chain Attack

I gave a talk recently about the state of software supply-chain attacks, and afterwards people kept coming back to the two compromises I’d pulled apart by hand, more than to any of the industry-wide numbers. This post is the written version of that part. Part 2 will pull back to the wider picture (XZ Utils, tj-actions, Trivy, and what actually helps); this one stays on the two incidents I looked at directly.

[Read More]