@Areeb_Soo_Yasir@mastodon.areebyasir.com
Post #873509
2026-03-24 19:42 UTC
Scary #Github #supplychain #cybersecurity attack on #Aquasecurity #docker images
This one is a classic issue of accidentally putting credentials, tokens or keys into what is pushed onto Github. It happens much more than people think.
I advocate for completely private build process and the scaling back of public repositories as it is easy to see how to surreptitiously modify code to inject malware into an image.
https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know/
Replies (0)
No replies.