TL;DR: We disclosed to Chainguard in December 2023 that one of their GitHub Actions workflow was vulnerable to "pwn request", potentially impacting the integrity of Docker images signed by their cosign Terraform Provider. Fortunately, this ended up being a near-miss incident. We also introduce the Living Off The Pipeline project, which inventories tools used in build pipelines that have RCE-by-Design features.
Boost Security is a Canada-based DevSecOps automation platform that offers solutions such as risk governance, and software supply chain security for enterprises.