tag: Supply-Chain-Security · 5 items
- Platform/SRE — Skip
- CI/CD — Learn: Illustrates a prompt-injection attack vector where malicious repo content hijacks an AI agent’s pre-approved command scope; informs how to think about sandboxing agent-assisted pipeline steps, but no deadline or active exploit anchor.
- Leader — Learn: Useful framing for setting policy on where and how AI coding agents are permitted to run in the development workflow, particularly around isolation boundaries — but no decision is forced today.
- Platform/SRE — Skip
- CI/CD — Plan: Teams that publish npm packages via their release pipelines should review the new dual-use metadata requirement to ensure compliance before enforcement begins; no hard deadline surfaced in the item, so schedule this in the next pipeline audit cycle.
- Leader — Learn: npm’s automated publish-time scanning strengthens the ecosystem’s supply-chain posture; worth noting as a positive signal when reviewing org-wide software supply-chain policy, but no leadership decision is required now.
- Platform/SRE — Skip
- CI/CD — Learn: Vendor-authored post highlighting how AI coding agents can leak credentials into build/deploy contexts; worth evaluating your secret isolation controls if agents touch pipelines, but no concrete deadline or confirmed compromise here.
- Leader — Learn: Surfaces a real risk category—AI agent access to secrets in the software supply chain—worth factoring into your AI tooling policy and golden-path standards, though this is Docker marketing with no specific incident or actionable deadline.
- Platform/SRE — Skip
- CI/CD — Learn: Beta feature that auto-opens MRs to patch vulnerable dependencies and iterates until the pipeline passes — worth evaluating once GA, but pre-GA status caps this at Learn for now.
- Leader — Learn: Beta capability targeting the OWASP dependency backlog and compliance remediation windows (PCI-DSS/FedRAMP 30-day deadlines); monitor for GA before considering for the golden path.
- Signals: breaking-change flagged
- Platform/SRE — Skip
- CI/CD — Plan: New GA endpoints let teams manage secret scanning custom patterns as code, enabling IaC-style enforcement of scanning policies across repos; schedule adoption as part of supply-chain hardening this quarter.
- Leader — Skip
- Signals: GA announcement