Supply Chain Attacks Slip Through Automated Builds
DevOps engineers face increasing risks from supply chain attacks and insecure infrastructure code. They are battling inconsistent code practices, outdated infrastructure, and the difficulty of auditing compromised builds due to malware self-deletion. The reliance on external dependencies and automated pipelines creates vulnerabilities that are difficult to detect and remediate.
SOURCES (60)
“I'm not able to verify https://github.com/d buckner/bloud/pull/57 with my lima local backend. It's worth creating some red e2e test cases first and using those to drive fixes. I can then verify the changes across all 3 backends.”
“I just started an AWS instance using Debian and was in the process of hardening it. I installed Tailscale, got it fully authorized, then installed Cockpit. That’s when I realized that since I log in to AWS using a .pem key, I don’t have a root user password. That’s where I messed up. I was following the steps from memory and forgot one vital step: I forgot to set a password for the admin/root account. I then edited the sudoers file to remove NOPASSWD , and after that I typed sudo -k , which imme”
“mentioned this in passing in another thread but it turned out worse than i thought so writing it up properly i self host n8n and was poking at Zie619/n8n-workflows, which is the repo most people end up at when they want example workflows. tried to filter it for anything using langchain nodes and got zero hits out of 2061 files turns out the node types got overwritten. the nodes are still there with names like "OpenAI Chat Model" but the type field on them says n8n-nodes-base.noOp. whic”
“Rewritten 2026 09 03. The original root cause in this issue was wrong. I claimed that merging a workflow file mid session poisons every in flight session's push, because branches carry a stale copy of the changed file and GitHub compares against current main. That theory is dead: four sessions dispatched in the same 9 second window as 119 pushed successfully, and their branches are based on f40b44343 — the very merge commit I thought they predated. The dispatcher fetches fresh at the agent step,”
“Preflight Checklist [x] I have searched existing issues and confirmed this has not already been suggested. [x] This is a product or documentation improvement, not a support request. Request Type Other Affected Area Extension or Module Problem or Use Case Currently, among the official extension plugins, two plugins are no longer functional: PAYEER This platform has ceased operations. Paygate The platform has shut down; the website is no longer accessible. <img width="2033" height="1605" alt="Imag”
“npx eslint packages/ apps/ fails on the flat config migration. Pre existing, and noted in the Bessel harvest handoff's "things a new agent will trip over". The compounding problem is that npm run lint is not a CI step , so nothing notices. .github/workflows/ci.yml runs npm run build , npm run typecheck:tests and npm test only. A lint script that is both broken and unwatched is worse than no lint script, because it reads as coverage that isn't there — the same failure mode as the LFS smudge that”
Hi, and thanks for publishing this Secure DFU client. We are evaluating nrf52 ble dfu as a Python/Bleak client for interoperability testing and deployment against a Nordic Secure DFU compatible service. The…
“Every Release run on main since 2026 09 02 fails at the publish step. npm now demands a 2FA OTP that the classic NPM TOKEN cannot satisfy, so yarn npm publish errors with: ( not otp is the sentinel changesets writes to stdin in non interactive mode so it can classify the result as failed:needs 2fa .) OIDC trusted publishing is exempt from the OTP requirement, and the pieces are already in place: Yarn 4.10.3 — the version this repo pins — is the release that shipped the scoped package OIDC fix (y”
“Shipped a fix this week for a bug that only showed up on a cold start (first launch after the machine had been off), never on a warm restart. The symptom: every proxy fetch on cold start failed with "no proxy available," even though the proxy pool was populated and healthy. No stack trace, no crash, the app just silently fell back to a direct connection instead of raising anything. Root cause: a shared asyncio lock was created once at import time, before any event loop existed yet. On”
“Submission checklist [x] This is a bug, not a usage question. [x] I added a clear and descriptive title that summarizes this issue. [x] I used the GitHub search to find a similar question and didn't find it. [x] I am sure that this is a bug in LangChain rather than my code. [x] The bug is not resolved by updating to the latest stable version of LangChain (or the specific integration package). [x] This is not related to the langchain community package. [x] I posted a self contained, minimal, repr”
“the overnight death is almost always the process, not the deploy. compose without a restart policy plus the node process exiting on an unhandled rejection means it's just gone and nothing brings it back. restart: unless-stopped on the service, then check docker events in the morning for the exit code. if it's 137 you got oom killed instead and you need swap or a bigger box, openclaw is happy to balloon during a long tool loop. if it came up once and then never again after a reboot, check”
“What problem does this solve? 16 / the local .terragraph/lock serializes two CLI processes on one machine, one checkout . That is a real race (shared tfvars, TF DATA DIR , saved plans, module .terraform.lock.hcl , vendor vs inspect). It is not the collaboration problem. Two people, or a laptop and a remote runner, each have their own working tree. Local files do not collide, the flock is invisible across machines, and whichever tree terragraph apply is pointed at becomes the graph that gets appl”
“scripts/test baseline.sh is the only sanctioned path from a measured test count to the four places that publish it. It needs cargo nextest and a full workspace build, and apps/sysknife shell pulls in WebKit, GTK, AppIndicator and librsvg. A contributor without those cannot regenerate the artifact, and has no supported way to say so. Why it matters Three contributors hit this in ten days, and the workaround each reached for is the one 278 exists to prevent. 340 recorded 1831 from the known Linux”
“" tdd doctor mis prescribes cross feature adoption + missing flat→namespaced migration\n\nWave 1 rebuild (post 827), fresh project: spec 001 completed on the PRE fix binary (its artifacts live at legacy flat paths), then spec 004 ran on the POST fix binary (artifacts namespaced under test/tdd/004 dependency injection/ ).\n\n What happened\n\n zfa tdd doctor 004 dependency injection reports 21 drifts like:\n\n \n\nBut those flat files are OWNED — by feature 001 (confirmed: specs/001 app bootstrap”
“It seems this was introduced with https://github.com/flathub/org.xonotic.Xonotic/pull/41 and still occurs when testing https://github.com/flathub/org.xonotic.Xonotic/pull/42, the last known good version "Rename the Xonotic patch ( 38)" (using runtime 24.08) can be installed with flatpak update commit=bae340f163ca32d5ede30077c4fb90ba59c4ffa12bddf557b456197ad645c5e9 org.xonotic.Xonotic . The datestamp is displayed in the bottom right of the corner of the console, and printed by the version command”
“We already prioritize past raw severity, KEV and EPSS for exploit signal, public facing assets weighted higher. It helped but the backlog is still huge, mostly dependency findings we are not sure we even call. We trialed one reachability tool already. It looked great until it flagged a reachable critical that was sitting behind an internal only vpc nothing outside can touch. The code path was real, the exposure was zero and i was back to explaining to a dev why the tool and i disagreed. That is”
“Depends what you mean by breakage, the loud failures are Outlook, the quiet ones are backup and monitoring agents”
“Found while reviewing 651. 651 fixed a fixture bug — three gliner relex e2e fixtures hardcoded interpreter root: None , so on a host with a uv provisioned CPython the jail got no bind for the interpreter and the worker died as a contentless Protocol(EarlyExit) . The bug survived for months for one reason: those tests skip as pass, and nothing can force them to run. The same PR added KASTELLAN GLINER RELEX REQUIRE E2E for the Python suite, where a skip now becomes a failure (and, via a conftest.p”
“I was giving a bit of thought, I can't just deploy my services directly to a customer's vpc as via root access they can just see my code. Be it docker running on an ec2 or eks. If I dont go ahead with the control/data plane split, what options do I have to protect my code? Will i have to go to the OS level and build my own AMI etc with attestations and key verifications and stuff at each stage, or use something like nitro conclaves or nvidia confidential compute or something along those”
“Not a package, more a two-line habit in my release script that has saved me twice: after the build, unzip the artifact and confirm the JS bundle is actually inside it. I shipped a React Native release AAB that installed fine and opened to a white screen. Nothing failed in the build. gradle saw a stale generated bundle, decided it was up to date, and packaged no JS at all. Deleting the generated bundle before the build is the fix, but the only thing that catches it before users do is listing the”
“Split out of 3800 (PR 3883) on roborev job 358 finding 2, at the lead visible boundary of that issue's funded slice. The gap 3800 gave a SIDE lane component that detects a tree capture failure a verified escalation ladder , because its normal channel — appending to $LOG DIR/tree integrity.fail — is a file on the very filesystem that may be full: 1. marker append (carries the reason) 2. truncate its own .result (O TRUNC allocates nothing) → unread verdict → OVERALL=FAIL 3. unlink its own .result”
“The repository has no SECURITY.md and the site serves no /.well known/security.txt . Someone who finds a vulnerability has no documented way to report it. This matters more than usual here. The project invites scrutiny of its cryptography, the relay is deployed and reachable, and the README makes specific claims about what the server can and cannot see. Inviting that scrutiny without giving people a route to report what they find is the wrong way round. Two files: SECURITY.md at the repository r”
“Problem make publish cannot complete. It would fail at step 5/16 , cargo publish p aimdb tokio adapter , and reordering the list does not fix it. Three workspace library crates are absent from the publish list entirely: aimdb uds connector aimdb serial connector aimdb tcp connector None of them exist on crates.io. Two published crates need them anyway: aimdb client has optional dependencies on all three ( transport uds , transport serial , transport tcp ). cargo publish requires every dependency”
“AGENTS.md documents a manual release path: The middle step does not work. npm run pack is: Running it from a clean build: Root cause scripts/build.ts copies package.json into dist/ verbatim : So dist/package.json carries the repo's scripts block, including "prepare": "npm run build" . npm pack runs prepare , which runs tsx scripts/build.ts — but the cwd is now dist/ , and dist/scripts/ does not exist. It dies before packing anything. Even if prepare were not there, the pack would still be wrong:”
“Impact Every branch based on main after b1fde6c fails all 109 Validation tests jobs with AxiosError: Request failed with status code 502 . Confirmed on 680, 682, 684 and 686, none of which touch the validation backend. main itself is red. No PR that reaches the validation stage can go green until this is fixed. Root cause 651 merged at 14:36:32 UTC today and bumped @opentelemetry/sdk trace node from ^1.18.1 to ^2.11.0 in packages/otelbin validation image , the AWS Lambda that serves server side”
“What Observed live. The SLM frontend's build output directory contains a single file — favicon.svg — and no index.html and no assets/ . The web server therefore has nothing to serve and answers 403 for the whole /slm/ tree, directory listing being denied. Everything else is healthy, which is what makes this worth filing rather than just fixing: | | state | | | | | all 10 autobot services | active (running) | | SLM frontend source ( index.html , package.json , node modules ) | present | | SLM fro”
“mimir config loader failed for at least seven minutes today with six pods in Error and 0/1 completions, blocking every alert rule update for every cluster, and nothing surfaced it. I found it only by manually checking the Job while verifying an unrelated change. Why it is silent mimirtool rules sync failing does not remove already loaded rules. The ruler keeps evaluating whatever it last accepted, so every dashboard and every existing alert looks completely healthy. The only observable symptom i”
We have an ongoing issue where one of our apps has started returning 500 status codes a few times a day on sending the splunk events. This is random and can't be…
“Added an opt-in cost-sensitivity parameter to how a production verifier picks its live decision threshold last week. The obvious "safe" default was 1.0, framed as "no change from today." Before shipping it, I checked the actual math instead of trusting the framing, and it would have silently moved every existing tenant's live threshold the moment anyone touched the new parameter, with zero warning. I run CacheVerifier, a small hosted service that fine-tunes a verifier mod”
“Yeah, I'll probably try to detect such cases and warn during onboarding. It's easily done.”
“Yeah, that’s the scary part. Supply chain attacks make “I only expose a reverse proxy” feel way less reassuring”
“Maybe you haven’t talked to many security professionals. Supply chain attacks are easiest to execute on small dev teams (vibe coders) who may not notice their projects have been hijacked.”
“Goal GET /v1/platform is the unauthenticated discovery document every client reads — issuer, API and console URLs, client ids, branding. It does not say which build is serving it , so there is no non destructive way to find out whether a released fix is actually deployed. That has a concrete cost. Over the last two days three fixes of mine were merged and released, and each time the only question that mattered was "is it live on api.erunpaas.com yet?" — with no way to ask it: For a new route , t”
“The scheduled Guardian run failed , which means something is broken on the live site. Run: https://github.com/TEARN1/The Gruvs/actions/runs/33448015010 One of these is true: Schema drift — a query no longer matches the database, so a feature is silently dead (this is how RSVP, Crews, polls and tickets broke without anyone noticing). Health — thegruvs.com does not boot, is throwing errors, or is no longer installable as an app. Open the run above for the exact failure.”
“Tested against v0.4.0 ( darwin arm64 release tarball; checksums.txt sha256 matched, and its sigstore bundle verifies with cosign against https://github.com/okfcli/okf/.github/workflows/release.yml@refs/tags/v0.4.0 ). What is missing Both validate and lint report warnings and exit 0 , and neither accepts a flag: So there is no supported way to make a CI job or a commit hook fail on a warning. A warning that nobody is obliged to act on is not a gate — it is a log line, and in a repository that any”
“Gap \ ahood update [<owner /<skill ...]\ with no arguments re resolves and re installs every skill in the lockfile to its current \"latest\", with zero preview step. There's no way to ask "what would change" before committing to it no version diff, no listing of which skills are actually behind vs. already current. For a tool clearly aimed partly at CI/agent driven usage (per the setup docs' \ AHOOD TOKEN\ guidance), a silent mass update with no dry run is a real footgun: one \ ahood update\ cal”
“Bug 1: interrupted update desyncs compose.yml and config.json pullAndPersist ( cli/cmd/update pull.go ) writes compose.yml with the new image pins before the image pull runs ( docker compose pull reads the image refs it pulls from that file), and only persists config.json (the new ImageTag / VerifiedDigests ) after the pull succeeds. On any pull error it rolls compose.yml back to its prior contents via an explicit if err != nil { rollback() } branch. The CLI has no signal handling anywhere ( gre”
“The above is referring to TeamPCP. They harvested those credentials through GHA. Risky Business has some good coverage on it. Moral of the story is pin your GHA modules through SHA hash, not version. Kind of orthogonal to self-hosting, but the general advice stays the same--rotate credentials, keep stuff up to date, and just show even mild interest in not getting your shit hacked, and you'll be fine. Credential harvesting is a crime of opportunity.”
“> Lots of teams that are supposed to be in charge of security don't ask "does this CVE affect us", but simply shift the burden of patching downward and outwardUnfortunately, I've had many a frustrating session with compliance auditors who do not care that it couldn't affect you, you're required to meet the PCI-DSS deadlines of 90 days for low, etc, and I've seen security groups force to accept that this is what they have to do, and then get the unfortunate task of dealing with engineers pissed o”
“Surfaced by an external qualification focused assessment of the public repo, cross checked directly against source (2026 08 31). This is a release/configuration management defect , not cosmetic — for automotive software, version identity feeds traceability, SBOM, defect tracking, and field diagnostics. Confirmed drift (checked against current main ) | Source | Value | | | | | README.md badge / CHANGELOG.md / tools/codegen.py:103 version | 1.12.0 | | core/uds types.h:38 42 UDS SUITE VERSION / UDS”
“Read the exposure section first this repo's situation differs from the other repos I am cross posting to. .github/release please config.json exists here (one package "." , release type: node , no component ), but there is no .github/workflows/release please.yml . The workflows present are audit.yml , ci.yml , dependabot auto merge.yml and publish.yml . So the config is currently orphaned nothing reads it. That is worth resolving on its own terms (either wire up release please or delete the stale”
“Summary Two related things, one small fix for each: 1. Every MCP tool declares "additionalProperties": false , but the server doesn't enforce it. An unknown argument is accepted, the call returns success, and the content is written nowhere. 2. .lovelace/AGENTS.md tells agents to add a comment when handing a ticket back, but no MCP tool can write one. Agents follow the instruction, pass comment to update ticket , get success, and lose the text. The good news on (2): addComment already exists and”
“Description Update checker checks for updates, but never shows a dialogue without manual request”
“Only honest commits by good actors are reviewed. Good for QA but useless for security.Cryptographic signing is not enforced for commits or reviews, so an attacker that controls a single maintainer Github API key could make a PR with a burner account then "review" and merge their own PR. Time it right and bury it in a dependency of a dependency and you are likely to get away with it. Especially considering they also do not do full source bootstrapping or enforce deterministic builds so including”
“Summary Book's Bash tool kills a foreground command at 120 s, and the model has no way to ask for more . npm run check — the gate CLAUDE.md tells Book to run before calling work done — takes longer than that on a normal machine. So Book, driven to build Book, cannot run its own gate, and the failure it gets back carries no output to reason about. Found while driving Book ( print ) to implement a fix on fix/windows kill completion . Evidence From one print mode run's tool records: Eight Bash call”
“Problem There is no way to tell over HTTP which build is running. /status reports only "version": "0.1.0" (from CARGO PKG VERSION , src/server.rs:566 ), and /metrics emits kb build info{version="0.1.0"} 1 with no revision label ( src/server.rs:746 ). The git SHA exists only as the image's org.opencontainers.image.revision OCI label. That label is only reachable with Docker access to the deployment host. Verifying "did my deploy actually take effect" — the first question after every release — is”
“Curious how everyone else handles this. When a new CVE or vendor advisory comes out, how do you figure out if it actually applies to anything you’re running? I end up checking the product, version, vendor notes, sometimes CISA, and then figuring out whether it’s actually relevant or just more noise. I’ve been messing around with a small tool that takes the advisory and a product/version and tries to tell you whether it looks relevant and what still needs to be verified. I’m not really trying to”
“Split out from 757, which is the underlying installer defect. This one is about why that defect was invisible. Symptom GET /api/companion/release returns a rich answer when the check cannot reach a verdict — error (e.g. github returned HTTP 403 , a socket error class) and note ( install has no release tag to compare ). The Admin tab reads neither. adminUpdateAvailable() in llm systems manager/frontend/js/admin.js is: Anything other than true renders nothing into the System Health warnings, and t”
“BLUF Adds SECURITY.md . Four packages are published and installable, and someone who finds a vulnerability in one has no stated private channel — so their reasonable default is a public issue, which discloses the flaw to everyone before a fix exists. What is actually true right now Private vulnerability reporting is already enabled on the repository: So the channel exists and works. What is missing is the file that tells anyone it exists. GitHub surfaces SECURITY.md in its own UI — the Security”
I ran into the same issue with 117 GB of orphaned Adobe MSP files, and another test machine had around 300 GB. I made a small open-source PowerShell tool that checks whether…
“Early Saturday morning we started getting a stream of alerts from Microsoft Defender regarding our Primary and Additional Polling Engines. Malware Name: Behavior:Win32/SuspiciousAssembly.AppDomainManagerType.A The malware file path: behavior:_process: was all over the place. Some examples: Malware file path: behavior:_process: C:\Windows\System32\wbem\WmiPrvSE.exe, pid:2208:557######2;file:_d:\program files (x86)\solarwinds\orion ~ Malware file path: behavior:_process: C:\Program Files\Common Fi”
“Yes. Tells me when people are trying to tamper with other settings on Linux systems.”
“I was reading a Huntress blog about the recent PaperCut exploit, and they detected it based on unusual commands like whoami and enumeration of the local administrators group. I ran a series of "weird" commands in my environment, and I noticed that Defender for Endpoint did not blink an eye. Some were AD information gathering commands. That was a little surprising to me. In fact, I actually thought maybe MDE was broken, so I ran an EICAR test, and it did detect that. So it seems like MD”
“The checkout the timers run from, /home/antranig/Developer/gqlc/gqlc, is on a DETACHED HEAD. km deploy refuses it: km: deploy: /home/antranig/Developer/gqlc/gqlc is parked on 'a detached HEAD', not master Measured 2026 08 29 by Աստղիկ while pinning cmd deploy's no argument path for bd gqlc akp4w. git C .../gqlc rev parse abbrev ref HEAD returns HEAD; git log oneline 1 returns d1f621ab, which IS current origin/master. WHY THIS READS HEALTHY AND IS NOT. Every instrument the town has says ok right”
“Bug: Panel initiated node update is hard killed by the 10s client timeout, leaving nodes broken Environment Panel: PasarGuard v5.2.1 (Docker) Node: pg node update flow via pg node service , node serviced v0.0.2 Node image: pasarguard/node:latest (published 2026 08 29) 3 nodes affected simultaneously (USA 1, LT 1, GK 1), observed 2026 08 29 21:49 UTC Summary Clicking Update on a node in the panel triggers a single synchronous REST call from the panel to the node ( POST /node/update ). The panel s”
“I dont deploy apps with winget. I deploy apps with robopack. But the repository that robopack uses to build instant apps is winget. So when the app is not in winget, it is not available as instant app in robopack.”
