Why software delivery cannot depend on trust alone

Trusted pipelines can ship untrusted code. The AsyncAPI attack shows why provenance alone isn’t enough. jpmellojr.blogspot.com/2026/08/why-... #AppSec #SupplyChainSecurity #DevSecOps #Upwind Attackers turned the trusted AsyncAPI CI/CD publishing pipeline against its users, and the provenance checks all came back clean. more

1 reportother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Why software delivery cannot depend on trust alone

stream:bsky-jetstreamother40d ago kagi ↗

Trusted pipelines can ship untrusted code. The AsyncAPI attack shows why provenance alone isn’t enough. jpmellojr.blogspot.com/2026/08/why-... #AppSec #SupplyChainSecurity #DevSecOps #Upwind Attackers turned the trusted AsyncAPI CI/CD publishing pipeline against its users, and the provenance checks all came back clean. more