Home > Supply Chain Attacks on Open Source

2026 Aug

https://github.com/advisories

GitHub Actions Preventing Pwn Requests

Adnan Khan: GitHub Actions Cache Poisoning

OpenSSF: Trusted Publishing for all Package Repositories

npm Trusted Publishing generally available

USENIX Security '25: Securing Packages in npm, Homebrew, PyPI, Maven Central, and RubyGems

https://slsa.dev

https://github.blog/changelog/2026-06-25-npm-adds-preventive-account-protection-for-high-impact-accounts/

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/

https://github.blog/changelog/2026-06-26-read-only-actions-cache-for-untrusted-triggers/

https://github.blog/changelog/2026-04-06-npm-trusted-publishing-now-supports-circleci/

https://github.blog/changelog/2026-06-09-upcoming-breaking-changes-for-npm-v12/

https://github.blog/changelog/2026-05-22-staged-publishing-and-new-install-time-controls-for-npm/

https://github.blog/changelog/2026-07-14-dependabot-version-updates-introduce-default-package-cooldown/