Security & supply chainGTIG and Mandiant publish a supply-chain hardening playbook aimed at CI/CD teams
Google's Threat Intelligence Group and Mandiant have released a joint guide on defending against software supply chain compromise, mapping four control categories onto the concrete pipeline levers most teams already own: short-lived tokens, ephemeral runners, package cooldowns and dependency verification.