security1 distinct publisher
Shai-Hulud's fourth wave shipped with valid provenance, and that is the finding
The poisoned keyv releases were signed by GitHub Actions and the attestation was accurate. It certified a build whose source had already been taken over.
Publishers:scworld.com
Reality
- Evidence34
- Adoption46
- Hype gap+18
- Incentives76
- Confidence41