The provenance on @7nohe/openapi-react-query-codegen was accurate about every question it was built to answer, which is why the Docker Security Dispatch reaches instead for a five-day resolution cooldown that npm ci does not apply.
Reality
- Evidence47
- Adoption
- Insufficient
- Hype gap+12
- Incentives72
- Confidence55
Akamai says the May 11-12 wave poisoned a CI cache and minted publish credentials from inside a trusted build, so the attestation it produced was honest. Any gate that only checks for provenance would have passed it.
Reality
- Evidence38
- Adoption33
- Hype gap+9
- Incentives74
- Confidence44
Socket says all ten bad tarballs of @7nohe/openapi-react-query-codegen carry genuine GitHub Actions attestations, which is what you get when the attestation covers where a build ran rather than who wrote the commit it built.
Reality
- Evidence66
- Adoption58
- Hype gap+10
- Incentives72
- Confidence57
Attackers moved upstream into the project's own repositories and release workflows, so the attestations checked out. Publisher reputation no longer tells you a build is clean.
Reality
- Evidence42
- Adoption28
- Hype gap+22
- Incentives82
- Confidence40
The poisoned keyv releases were signed by GitHub Actions and the attestation was accurate. It certified a build whose source had already been taken over.
Reality
- Evidence34
- Adoption46
- Hype gap+18
- Incentives76
- Confidence41