#attestations
Tagged “attestations”
2 articlesSecurity & supply chain
npm provenance attestations get worn as camouflage in a new worm-style attack
The New Stack reports a supply-chain campaign against npm that turned the exact control CI/CD teams have started to lean on into cover. Attestations do not become useless overnight, but reading them as a green light gets harder starting now.
Aug 12, 2026 · Tomás VegaSupply chain securityImage verification, one layer below admission
A CNCF post outlines a Node Resource Interface plugin that verifies SLSA, VEX and VSA attestations at CreateContainer time inside the container runtime, closing gaps that admission webhooks can miss.
Jul 31, 2026 · Tomás Vega