Safeguard
Tag

ci-cd-security

Safeguard articles tagged "ci-cd-security" — guides, analysis, and best practices for software supply chain and application security.

100 articles

DevSecOps

Where to Put the Security Gate So It Does Not Stop the Line

Most badly behaved security gates are correctly configured checks in the wrong position. The four places a check can run, what each can afford, and the rollout sequence that keeps a gate alive.

Sep 17, 20266 min read
Security News

How a GitHub Actions Flaw Turned a 61-Million-Download Python Package Into a Cryptominer Delivery Vector

The Ultralytics YOLO compromise in December 2024 didn't touch a single line of reviewed code. It exploited the CI/CD pipeline that builds and publishes the package instead.

Sep 16, 20266 min read
Vulnerability Analysis

Two Supply Chain Compromises, Two Different Failure Modes: TanStack npm and ASUS Live Update

A live npm registry attack against TanStack's trusted GitHub Actions publishing pipeline and a years-old ASUS Live Update client backdoor show two distinct ways software trust gets weaponized.

Sep 16, 20265 min read
Vulnerability Analysis

A CVSS 10.0 That Only Reads Files: GitLab CVE-2026-85706

An unauthenticated attacker reads arbitrary files from a GitLab server. There is no code execution, and it still scores 10.0 — because on a source host a read primitive is a credential incident.

Sep 16, 20266 min read
Vulnerability Analysis

CVE-2026-63077: Your Build Server Is a Credential Store With an Open Port

An unauthenticated attacker sends a crafted object to TeamCity's agent polling endpoint and gets OS command execution as the server process. Every credential the build server holds sits downstream.

Aug 11, 20267 min read
Open Source Security

npm Classic Tokens Are Gone. The keyv Worm Shows Why That Mattered.

Every npm classic token has been permanently revoked — unrecoverable, unrecreatable. Teams treated it as a chore. Then a worm propagated across 444 packages on exactly that kind of credential.

Aug 7, 20266 min read
Threat Intelligence

Bring Your Own Runtime: Why the keyv Payload Downloaded Bun

The August 2026 npm worm did not run its second stage in Node. It downloaded a standalone Bun binary first — a choice that defeats a surprising amount of build-pipeline monitoring.

Aug 6, 20266 min read
Open Source Security

npm 12 Turned Install Scripts Off. The keyv Worm Used a preinstall Hook Anyway.

Install scripts have been off by default since npm 12 shipped in July 2026. Four weeks later a worm propagated through preinstall hooks. A default is not a control until you prove it is enforced.

Aug 5, 20266 min read
DevSecOps

npm CLI Login in CI: Tokens, npm-cli-login, and Safer Patterns

The npm-cli-login package automated interactive npm login for CI pipelines — a pattern that npm's 2025 authentication overhaul has made both broken and unnecessary. Here is what to use instead.

Aug 5, 20267 min read
Vulnerability Analysis

CI/CD pipeline supply chain attacks explained

A breakdown of how CI/CD supply chain attacks work, from SolarWinds to the 2025 tj-actions/changed-files breach, and how to detect and stop them.

Jul 31, 20266 min read
Vulnerability Analysis

Argument injection vulnerabilities explained

How argument injection (CWE-88) vulnerabilities work, real CVEs like PHPMailer and Git ssh URLs, and how teams detect and prevent CWE-88 flaws.

Jul 28, 20267 min read
DevSecOps

The tj-actions/changed-files GitHub Action Supply Chain C...

CVE-2025-30066 exposed how a compromised tj-actions/changed-files GitHub Action leaked CI/CD secrets into build logs across 23,000+ repos. Timeline, impact, and fixes.

Jul 27, 20268 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.