Originally published at harshit.cloudhttps://harshit.cloud/blog/lazy-security-part-2-github-actions on 2026-04-12.
Last March, someone with write access to the trivy-action repo rewrote 76 of its 77 version tags in place. The tags still resolved t...
Originally published at harshit.cloudhttps://harshit.cloud/blog/lazy-security-part-1-supply-chain on 2026-04-05.
A few months ago a friend's CI pipeline tried to install a package none of us had heard of. The build failed. The error wasn't a missi...