Short-lived OIDC for CI: kill every long-lived GitHub Actions token
AWS OIDC, GCP WIF, Azure federated credentials
May 3, 20268 min read21

Search for a command to run...
Articles tagged with #github
AWS OIDC, GCP WIF, Azure federated credentials

A 3-year patient infiltration. One 500ms anomaly. Zero automated defenses. Here's the full architecture of what happened, what should have stopped it, and how to build a self-healing supply chain security system into your IDP, today.
