I gave a talk recently about the state of software supply-chain attacks, and the part people kept asking about afterwards wasn’t the industry-wide statistics — it was the two compromises I’d pulled apart by hand. This post is the written version of that part. Part 2 will pull back to the wider picture (XZ Utils, tj-actions, Trivy, and what actually helps); this one stays on the two incidents I looked at directly.
[Read More]