
When Your Security Scanner Gets Compromised
Security
10 min readSupply chain security, SLSA, OIDC, secrets management, policy as code, and hardening.

When Your Security Scanner Gets Compromised


GitHub Actions Workflow Lockfiles Are Coming

GitHub Actions Artifact Attestations: SLSA Provenance and Supply Chain Defaults

GitHub Actions Permissions: Lock Down GITHUB_TOKEN


GitHub Actions OIDC Custom Properties: ABAC Cloud Access
GET TENKI