cache-poisoning githubactions bugbounty Turning Almost Nothing into a Supply Chain Compromise of Angular with GitHub Actions Cache Poisoning Mar 3, 2026
cicd ai github Copilot or Coconspirator - Tricking GitHub Copilot and Stealing all Your Secrets Jan 7, 2026
cicd bugbounty Who's SHA is it Anyway: Bypassing Google Cloud Build Comment Control for $30,000 Jul 21, 2025
bugbounty cicd githubactions Release-Drafter To google/accompanist Compromise: VRP Writeup Nov 12, 2024
bugbounty cicd github One Supply Chain Attack to Rule Them All - Poisoning GitHub's Runner Images Dec 20, 2023