The npm Worm Targets Your Test Pipeline: Hardening Playwright CI After Shai-Hulud
What the keyv and Bitwarden CLI attacks did to CI runners and AI coding agent config files, which defenses we verified on real npm versions (including one that npm 10 silently ignores), and a pull request check for files that run code on folder open.
ci cd · security · github actions
9 MIN
Updated