Our audit of Homebrew
blog.trailofbits.com | blog | #security-audit | #ci-cd | #macos | #supply-chain-security | #trail-of-bits | #package-manager | #homebrew
Summary
Trail of Bits' Open Tech Fund-sponsored audit of Homebrew found non-critical flaws enabling unexpected code loading and CI/CD attacks that could tamper with bottle builds and exfiltrate secrets.
- Published
- Collected
Skip to content