Testing
Container Image Signing with Sigstore and cosign in CI/CD Pipelines
In December 2020, attackers inserted a backdoor into a SolarWinds software update. In 2022, a malicious package mimicking a popular npm library was downloaded 300,000 times before removal. In 2024, the XZ Utils backdoor was only caught by accident. The pattern is consistent: software supply chain attacks work by