<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Software Supply Chain on ap7i.com</title>
    <link>https://ap7i.com/tags/software-supply-chain/</link>
    <description>Recent content in Software Supply Chain on ap7i.com</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 29 Apr 2026 18:13:11 -0400</lastBuildDate>
    <atom:link href="https://ap7i.com/tags/software-supply-chain/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>How a Single Semicolon Got Past GitHub&#39;s Push Pipeline</title>
      <link>https://ap7i.com/posts/github-push-pipeline-rce/</link>
      <pubDate>Wed, 29 Apr 2026 18:13:11 -0400</pubDate>
      <guid>https://ap7i.com/posts/github-push-pipeline-rce/</guid>
      <description>Wiz researchers found a critical RCE in GitHub&amp;rsquo;s git push pipeline on March 4. The fix on github.com landed 75 minutes later. The April 28 disclosure makes clear what nearly happened — and why GitHub Enterprise Server admins still have urgent work.</description>
    </item>
  </channel>
</rss>
