Observed Signal · Jun 30, 2026 · Technical Release · Source: DEV Community · Impact: 2/5 · Sentiment: Positive

CI ran untrusted code; cilock provides signed provenance

Executive Signal Summary

The article describes recent supply‑chain incidents where CI pipelines executed credential‑stealing code (a force‑pushed git tag in aquasecurity/trivy-action and malicious .pth files in litellm PyPI releases) and explains that existing CI workflow YAMLs cannot prove what code actually executed. It introduces CI/Lock (cilock), a tooling layer that traces a build process (via ptrace or eBPF), records files read, environment and artifacts, and produces an in‑toto/DSSE-signed attestation. The attestation plus a signed policy enables verification of exactly what ran during a build, improving provenance and mitigating supply‑chain risks in CI pipelines. Publication date: 2026-06-30.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Tooling that provides signed build provenance addresses software supply‑chain risks relevant to any organization that ships software; notable but not industry‑shifting and not specific to major adtech platforms.

SIGNAL RADAR

Track Real-Time CI supply‑chain security / build provenance Signals & Market Shifts

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • An attacker force-pushed 75 of 76 version tags in the aquasecurity/trivy-action repository, causing pipelines pinned to a tag to pull credential-stealing code.
  • Two litellm releases on PyPI shipped a credential stealer inside a .pth file that executes at Python startup without explicit import.
  • CI workflow YAML and pinned action source do not provide a signed record of what actually executed in a CI run.
  • CI/Lock (cilock) is a tool that traces a CI command (via ptrace or eBPF) and produces an in-toto/DSSE-signed attestation recording files opened, environment, and produced artifacts.
  • cilock supports signed policies (human-signed or GitHub Actions OIDC keyless signing) and provides run and verify commands for build-time provenance.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: Jun 30, 2026
Original Coverage Title: “Your CI ran code it should not have, and you cannot prove it did not”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

IdentityJun 8, 2026

Trivy March Supply-Chain Credential-Theft Campaign

A fast-moving supply-chain campaign beginning in late February 2026 compromised Trivy-related CI/CD artifacts and expanded across registries and images after incomplete remediation. An automated bot stole a privileged Personal Access Token (PAT) from CI, enabling attackers to push malicious artifacts to the Trivy VS Code extension and later publish a malicious Trivy binary (v0.69.4). On March 19 attackers force-pushed malicious commits to hundreds of Trivy Action tags and injected two Python infostealers that harvested environment variables, runner memory, SSH keys, cloud tokens and other secrets, exfiltrating them to attacker-controlled infrastructure or public GitHub repositories. Aqua Security disclosed the incident on March 1 and rotated credentials, but residual access remained. By March 24 the campaign moved into PyPI and NPM (poisoned Litellm packages) and Docker images; a new exfiltration endpoint (models.litellm.cloud) and additional targets (e.g., Checkmarx KICS) were reported. The reporting underscores that incomplete cleanup can turn a single breach into a sustained credential-theft campaign.

Read assessment
Large Language Models (LLM) & AIApr 10, 2026

Cert‑gating Tool Calls for Zero‑Trust AI Agents

A developer describes an open‑source agent security kernel that enforces zero‑trust for AI agents by cert‑gating every tool invocation. The kernel requires all tool calls to pass through an enforce_policy function which validates strict JSON schemas, attaches provenance-tagged values (pv/Prov), enforces taint-flow invariants (TAINTED never becomes TRUSTED), and checks scoped, time‑limited, budgeted capability tokens. Successful checks mint signed artifacts (e.g., TOOL_CALL_CERT.v1, TAINT_FLOW_CERT.v1) and all events are recorded in an append‑only Merkle trace; failures emit structured obstruction artifacts (PROMPT_INJECTION_OBSTRUCTION.v1). The project is MIT licensed, available at github.com/1r0nw1ll/agent-security-kernel, and published as a pip package. The design targets multi‑model orchestration use cases (Claude, GPT/Codex, open‑source models) and aims to close provenance-based prompt‑injection gaps.

Read assessment
InfrastructureMay 4, 2026

Enforce Kubernetes Image Provenance with Cosign & Kyverno

A developer experiment demonstrates enforcing image provenance in Kubernetes so the cluster only runs cryptographically signed container images. The workflow uses GitLab CI/CD as the build-and-trust origin, Cosign/Sigstore to sign and publish OCI image signatures, an OCI registry to store images and signatures, and Kyverno as a Kubernetes admission controller to verify signatures and enforce policies. The author tested the approach on a local MicroK8s cluster, published example GitLab pipeline snippets and a Kyverno ClusterPolicy that resolves image digests, fetches Cosign signatures from the registry, and allows or rejects Pod creation based on verification. A reference GitHub repository with code and configs is provided.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.