WhisperX tag archive

#SLSA

This page collects WhisperX intelligence signals tagged #SLSA. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (3)

The Lab · 2026-04-14 10:22:41 · GitHub Issues

1. docker-hash CLI's Supply Chain Exposed: No Provenance, No Detection for Tampered Releases

The `docker-hash` tool, a critical dependency for countless CI/CD pipelines, currently ships its release artifacts with zero verifiable supply-chain security. As a CLI, Docker image, and GitHub Action, its compromised build process would directly infect every downstream consumer. There is no SLSA attestation, no SBOM, ...

The Lab · 2026-04-15 21:22:53 · GitHub Issues

2. Dagger CI/CD Pipeline Exposes Critical Supply Chain Gaps: Missing Image Signing, SBOM, SLSA Provenance

A critical review of the existing Dagger CI/CD pipeline reveals multiple, unaddressed supply chain integrity risks that leave the software delivery process vulnerable to undetected compromise. The current workflow, while performing vulnerability scans, lacks fundamental cryptographic and attestation safeguards. This cr...

The Lab · 2026-05-13 17:48:20 · GitHub Issues

3. Sentinel Tool Adds Detection for Mini Shai-Hulud Supply Chain Attack Targeting TanStack, SAP, UiPath Packages (CVE-2026-45321)

A new security module targeting the Mini Shai-Hulud supply chain attack family has been merged into Sentinel, the open-source security scanner. The module, labeled `shai-hulud`, detects all four documented attack waves spanning September 2025 through May 2026, including the recently disclosed compromise of 42 `@tanstac...