Supply chain attacks are exploiting our assumptions
blog.trailofbits.com | incident | #supply-chain | #pypi | #supply-chain-security | #typosquatting | #build-pipeline | #sbom | #trusted-publishing | #package-registry
Summary
From typosquatting to poisoned pipelines, supply chain attacks exploit implicit trust in package registries; tools like TypoGard, Zizmor, and PyPI Trusted Publishing make trust verifiable.
- Published
- Collected
Skip to content