Skip to content

Add 2025 software supply chain attacks#139

Merged
mrbobbytables merged 12 commits intocncf:mainfrom
sivanahamer:main
Jan 14, 2026
Merged

Add 2025 software supply chain attacks#139
mrbobbytables merged 12 commits intocncf:mainfrom
sivanahamer:main

Conversation

@sivanahamer
Copy link
Contributor

Adding attacks 2025 to the new repository mentioned in: cncf/tag-security#1503

Copilot AI review requested due to automatic review settings December 7, 2025 16:49
@netlify
Copy link

netlify bot commented Dec 7, 2025

Deploy Preview for contribute-cncf-io ready!

Name Link
🔨 Latest commit c00ea6e
🔍 Latest deploy log https://app.netlify.com/projects/contribute-cncf-io/deploys/6967acb6c29b0100085e885c
😎 Deploy Preview https://deploy-preview-139--contribute-cncf-io.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This pull request adds documentation for three significant software supply chain attacks that occurred in 2025 to the CNCF TAG Security catalog. The additions align with the catalog's mission to capture diverse attack patterns for developing best practices and tools.

Key Changes

  • Added three 2025 supply chain compromise entries to the catalog index
  • Created detailed documentation for the Shai-Hulud self-replicating worm attack on npm
  • Created documentation for an npm phishing campaign targeting maintainer Qix
  • Created documentation for the nullifAI malicious ML model incident on Hugging Face

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 8 comments.

File Description
docs/community/tags/security-and-compliance/publications/catalog/index.md Added three new 2025 entries to the supply chain compromises table with appropriate links and compromise types
docs/community/tags/security-and-compliance/publications/catalog/2025/shai-hulud.md Documented the Shai-Hulud worm attack including impact, compromise type, and references
docs/community/tags/security-and-compliance/publications/catalog/2025/qix.md Documented the npm phishing campaign targeting Qix with impact analysis and related incidents
docs/community/tags/security-and-compliance/publications/catalog/2025/nullifAI.md Documented malicious ML models on Hugging Face with security implications

Copilot AI review requested due to automatic review settings December 7, 2025 17:03
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 4 out of 4 changed files in this pull request and generated 9 comments.

Copilot AI review requested due to automatic review settings December 7, 2025 17:14
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 4 out of 4 changed files in this pull request and generated 4 comments.

@castrojo
Copy link
Member

Can you try to pass the DCO bot thing? Thanks!

@sivanahamer
Copy link
Contributor Author

Done!

@nate-double-u
Copy link
Member

Thanks for this @sivanahamer!

Since this is coming in from the tag-security, should the same folks who would have approved cncf/tag-security#1503 approve this before merge?

@mrbobbytables, is it the intention that each tag has sway over their section of this site?

Copy link
Member

@brandtkeller brandtkeller left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for moving this over to this repository and navigating the updates - appreciate the patience.

@brandtkeller
Copy link
Member

@nate-double-u pausing to take final action on merge for any additional considerations from @mrbobbytables or yourself.

@mrbobbytables
Copy link
Member

Thanks for this @sivanahamer!

Since this is coming in from the tag-security, should the same folks who would have approved cncf/tag-security#1503 approve this before merge?

@mrbobbytables, is it the intention that each tag has sway over their section of this site?

yes, need to add the codeowners to the root to allow them to merge themselves 👍

I'll add it on the TODO

sivanahamer and others added 12 commits January 14, 2026 08:48
Signed-off-by: sivanahamer <sivanahamer@gmail.com>
…og/2025/nullifAI.md

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Sivana Hamer <sivanahamer@gmail.com>
Signed-off-by: sivanahamer <sivanahamer@gmail.com>
…og/2025/nullifAI.md

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Sivana Hamer <sivanahamer@gmail.com>
Signed-off-by: sivanahamer <sivanahamer@gmail.com>
…og/2025/nullifAI.md

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Sivana Hamer <sivanahamer@gmail.com>
Signed-off-by: sivanahamer <sivanahamer@gmail.com>
…og/2025/qix.md

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Sivana Hamer <sivanahamer@gmail.com>
Signed-off-by: sivanahamer <sivanahamer@gmail.com>
…og/2025/shai-hulud.md

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Sivana Hamer <sivanahamer@gmail.com>
Signed-off-by: sivanahamer <sivanahamer@gmail.com>
…og/2025/qix.md

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Sivana Hamer <sivanahamer@gmail.com>
Signed-off-by: sivanahamer <sivanahamer@gmail.com>
…og/2025/nullifAI.md

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Sivana Hamer <sivanahamer@gmail.com>
Signed-off-by: sivanahamer <sivanahamer@gmail.com>
…og/2025/qix.md

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Sivana Hamer <sivanahamer@gmail.com>
Signed-off-by: sivanahamer <sivanahamer@gmail.com>
…og/2025/shai-hulud.md

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Sivana Hamer <sivanahamer@gmail.com>
Signed-off-by: sivanahamer <sivanahamer@gmail.com>
…og/2025/shai-hulud.md

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Sivana Hamer <sivanahamer@gmail.com>
Signed-off-by: sivanahamer <sivanahamer@gmail.com>
…og/2025/shai-hulud.md

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Sivana Hamer <sivanahamer@gmail.com>
Signed-off-by: sivanahamer <sivanahamer@gmail.com>
@mrbobbytables mrbobbytables self-assigned this Jan 14, 2026
@mrbobbytables mrbobbytables merged commit ae2208d into cncf:main Jan 14, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants