Why software delivery cannot depend on trust alone
Trusted pipelines can ship untrusted code. The AsyncAPI attack shows why provenance alone isn’t enough. jpmellojr.blogspot.com/2026/08/why-... #AppSec #SupplyChainSecurity #DevSecOps #Upwind Attackers turned the trusted AsyncAPI CI/CD publishing pipeline against its users, and the provenance checks all came back clean. more