CuraDevOps

tag: Supply-Chain · 16 items

  • Platform/SRE — Learn: Docker’s extended security coverage and source-built images could reduce CVE surface on base images, but no EOL date or forced migration anchor exists — worth evaluating at next image refresh cycle.
  • CI/CD — Learn: Policy enforcement moving to developer machines and provenance guarantees through customized images are worth tracking for supply-chain hardening plans, but no deadline or breaking change makes this actionable now.
  • Leader — Skip
  • Signals: deprecation mentioned (no explicit date found)
2026-08-14 · HashiCorp Blog · source ↗ #packer#supply-chain#slsa
  • Platform/SRE — Plan: If your org builds custom AMIs or VM images with Packer, this GA release introduces native SLSA provenance that strengthens image supply-chain attestation — worth adopting this quarter as part of a platform hardening cycle.
  • CI/CD — Plan: Packer v1.16.0 adds native SLSA provenance generation to machine image builds; if your pipelines include image baking steps, schedule an update to enable provenance output and integrate verification into the release gate.
  • Leader — Learn: Packer’s native SLSA provenance support signals a maturing supply-chain posture for machine images, relevant to orgs building toward SLSA compliance — no immediate strategic decision required but worth factoring into policy planning.
2026-08-14 · GitHub Changelog · source ↗ #github#supply-chain#licensing
  • Platform/SRE — Skip
  • CI/CD — Learn: GitHub’s dependency graph now pulls license data from npm and PyPI registries, improving accuracy of license visibility in repos — useful context if your supply-chain compliance workflow relies on GitHub’s license detection.
  • Leader — Learn: More accurate license metadata in GitHub’s dependency graph reduces the risk of unknowingly shipping components with incompatible licenses — worth noting if the org uses GitHub for license compliance reviews.
2026-08-10 · Releases: argo-cd · source ↗ #argo-cd#gitops#supply-chain
  • Platform/SRE — Plan: New GA minor release of a tool platform teams operate on-cluster; appset concurrency and configurable webhook jitter are operationally relevant improvements worth scheduling an upgrade to this quarter.
  • CI/CD — Plan: SLSA Level 3 provenance for all container images and CLI binaries and new Source Integrity CLI support are meaningful supply-chain hardening steps worth adopting; plan to upgrade and enable provenance verification in deployment pipelines.
  • Leader — Skip
  • Signals: Argo CD 3.5 supported
2026-08-09 · GitHub Changelog · source ↗ #secret-scanning#github#supply-chain
  • Platform/SRE — Skip
  • CI/CD — Learn: GitHub expanded push protection to block additional secret types and added a new scanning partner; worth reviewing if your pipelines commit credentials that may now be flagged before merge.
  • Leader — Skip
2026-08-07 · CNCF Blog · source ↗ #supply-chain#ai-security#ci-cd
  • Platform/SRE — Learn: Useful framing for understanding how unsanctioned AI tools introduce new attack surfaces into the platform layer, but no specific infrastructure action or deadline is present.
  • CI/CD — Learn: Directly relevant to pipeline security thinking — AI extensions and agents in the build path are an emerging supply-chain risk worth evaluating, but no concrete deprecation, compromise, or deadline anchors an Act or Plan verdict.
  • Leader — Plan: Shadow AI in delivery pipelines is a policy and governance gap that warrants adding AI tool usage to supply-chain standards and acceptable-use policy; schedule a review of which AI integrations teams are using in pipelines before the next security audit cycle.
2026-08-06 · GitHub Changelog · source ↗ #github-actions#code-scanning#supply-chain
  • Platform/SRE — Skip
  • CI/CD — Plan: If your org uses GitHub code scanning default setup, evaluate adopting the new github-codeql-config-file repository property to standardize CodeQL scan behavior across repos without per-repo overrides.
  • Leader — Plan: This enables centralized enforcement of code scanning standards across the org’s repositories — worth incorporating into the golden path or security policy for teams already on GitHub Advanced Security.
2026-08-04 · GitHub Changelog · source ↗ #codeql#static-analysis#supply-chain
  • Platform/SRE — Skip
  • CI/CD — Plan: If pipelines use CodeQL for code scanning on Swift or Kotlin codebases, upgrade to 2.26.2 to gain language-version coverage for Swift 6.3.3 and Kotlin 2.4.10; no deadline, but worth scheduling this quarter.
  • Leader — Skip
2026-07-29 · GitHub Changelog · source ↗ #github-actions#supply-chain#security
  • Platform/SRE — Skip
  • CI/CD — Plan: GitHub now holds potentially malicious workflow runs for review in public repositories; audit your org’s Actions approval settings and ensure maintainers understand how to review held runs before merging external contributions.
  • Leader — Learn: GitHub’s new default protection against credential-stealing workflow attacks reduces supply-chain risk for orgs using public repos; worth noting as a positive vendor-risk signal when assessing GitHub Actions dependency.
2026-07-29 · GitHub Changelog · source ↗ #supply-chain#dependabot#security
  • Platform/SRE — Skip
  • CI/CD — Plan: Enable or verify Dependabot alerts are active across your repos to benefit from the expanded OpenSSF malicious-package coverage; no deadline, but this materially improves supply-chain detection in your dependency pipeline.
  • Leader — Plan: Broader malware signal coverage from OpenSSF integration strengthens your software supply-chain posture — confirm Dependabot alerts are enabled org-wide as a policy standard this quarter.
2026-07-28 · GitHub Changelog · source ↗ #github-actions#supply-chain#security
  • Platform/SRE — Skip
  • CI/CD — Plan: GitHub now holds unproven workflows pending approval on public repos — review your repository settings and approval workflows to ensure this protection is enabled and fits your release process.
  • Leader — Learn: A new GitHub platform-level control targeting supply chain attacks via compromised credentials; worth noting as a defense-in-depth signal for orgs that rely on GitHub Actions for public repositories.
  • Platform/SRE — Plan: Docker removing the cost barrier for hardened, minimal base images makes it practical to standardize on them across cluster workloads, reducing CVE surface without budget justification. Evaluate adopting Docker Hardened Images as the default base-image standard in your next quarterly planning cycle.
  • CI/CD — Plan: Hardened base images are directly relevant to build-time and artifact supply-chain security; with the free tier now available, it’s worth scheduling a migration of pipeline build images and application Dockerfiles to hardened variants as a supply-chain hardening step.
  • Leader — Learn: Docker making a previously premium security feature free reshapes the container security tooling landscape and is useful context for evaluating whether to formalize a hardened-image standard in the golden path, but no immediate strategic decision is required.
2026-07-16 · GitHub Changelog · source ↗ #secret-scanning#supply-chain#github
  • Platform/SRE — Skip
  • CI/CD — Plan: New secret types are now auto-detected in repo scans; review your secret scanning policy to ensure newly covered credential types (Resend, APIclub) are included in alerting and rotation workflows.
  • Leader — Skip
  • Platform/SRE — Skip
  • CI/CD — Learn: Bit-for-bit reproducible base images reduce supply-chain risk; worth following as a model if your pipelines use Arch-based images or if you’re evaluating reproducible build practices more broadly.
  • Leader — Skip
2026-07-15 · GitHub Changelog · source ↗ #dependabot#supply-chain#github-actions
  • Platform/SRE — Skip
  • CI/CD — Learn: Dependabot’s new default 3-day cooldown before raising version-update PRs reduces noise from yanked or quickly-patched releases; no pipeline changes required, but worth understanding if teams rely on same-day dependency PRs.
  • Leader — Skip
2026-07-11 · Grafana Blog · source ↗ #supply-chain#security#grafana
  • Platform/SRE — Learn: Grafana’s PIR confirms no customer production impact and no Grafana Cloud compromise from the TanStack npm attack; useful background on how supply chain attacks can reach observability vendors, but no operational change is required.
  • CI/CD — Learn: The report details how a compromised npm package triggered a ransom incident and exposed a missed credential rotation — valuable for evaluating the depth of your own supply chain audit and rotation runbooks, even though Grafana’s customer pipelines were unaffected.
  • Leader — Learn: Grafana’s independently audited transparency report (Mandiant confirmed no code tampering or repository poisoning) is useful context for assessing vendor security maturity; no strategic action is required since customer exposure was ruled out.