• Assessments
  • Events
  • Governance
  • Supply Chain Security
  • Blog
  • Supply Chain Security
    • Compromises
      • 1975
        • login-bell
      • 2003
        • debian
        • gentoo-rsync
        • kernel-repository
      • 2007
        • squirrelmail
        • wordpress
      • 2008
        • fedora
      • 2010
        • apache
        • aurora
        • fsf-website
        • proftpd
      • 2011
        • kernelorg
      • 2012
        • ruby-on-rails-github
      • 2013
        • apt
      • 2014
        • code-spaces
        • monju
      • 2015
        • ceph-and-inktank
        • juniper
        • xcodeghost
      • 2016
        • fosshub
        • gh-unicode
        • keydnap
        • mint
      • 2017
        • bitcoingold
        • ccleaner
        • elmedia
        • expensivewall
        • hacktask
        • handbrake
        • kingslayer
        • notpetya
      • 2018
        • aur
        • colourama
        • dofoil
        • event_stream
        • gentoo
        • gogetu
        • operation-red
        • unnamed-maker
      • 2019
        • canonical-github
        • electron-native-notify
        • monero
        • pear
        • purescript-npm
        • pypi
        • ros
        • shadowhammer
        • webmin-backdoor
      • 2020
        • nodejs
        • octopus_scanner
        • solarwinds
        • sonarqube
        • thegreatsuspender
        • trojanized-fdm
      • 2021
        • coa-rc
        • codecov
        • homebrew
        • klow-klown-okhsa
        • log4j
        • php
        • repojacking
        • travis-ci
        • ua-parser-js
        • vscode
      • 2022
        • auth0-source-code-leak
        • Comm100-live-chat-trojan
        • ctx-and-phpass
        • docker-hub-malicious-containers
        • dropbox-github-account-breach
        • fantasy
        • golang-buildpacks-compiler
        • intel-alder-lake-BIOS-leak
        • js-faker-colors
        • node-ipc-peacenotwar
        • okta-github-repo-leak
        • php-pear-compromise
        • pypi-malicious-packages
        • ruby-override
        • wp-apthemes
      • 2023
        • fake-dependabot
        • mathjs-min
        • packagist-maintainer-takeover
        • retool-portal-mfa
        • xmlsec-manageengine
      • compromise-definitions
    • Secure Software Factory
      • Images
      • secure-software-factory
    • Supply Chain Security Paper
      • secure-supply-chain-assessment
      • sscsp
      • Sscsp Images
Edit this page Create issue

This site may contain outdated or incomplete information.

Follow along or join the revision effort!

Cloud Native Computing Foundation logo
All CNCF Sites
© 2024 The CNCF Authors | Documentation Distributed under CC BY 4.0