SHA Pinning Is Not Enough
A few days ago I wrote about how the Trivy ecosystem got turned into a credential stealer. One of my takeaways was βpin by SHA.β Every supply chain security guide says it, Iβve said it, every subreddit says it, and the GitHub Actions hardening docs say it.
The Trivy attack proved it wrong, and I think we need to talk about why.
[link] [comments]