Axios Supply Chain Attack Reaches OpenAI macOS Signing Pipeline
3 points
1 hour ago
| 1 comment
| socket.dev
| HN
KaiLetov
28 minutes ago
[-]
The fact that OpenAI's pipeline had no minimumReleaseAge configured is surprising though. That's basically saying "run whatever npm published 5 minutes ago in a context that has access to my signing keys." For a company that size, with that attack surface, feels like this should've been caught in a security review.
reply