1
Use Canary Credentials to detect supply chain compromise
Source: dani-garcia/vaultwarden#7195 · opened by @dancho-atanasov-tracebit
I saw you're diligent and have put efforts hardening your GitHub Actions workflows and you managed to avoid the Trivy incident ( but I wanted to share what we're working on that might help in the future. I work at Tracebit and we've shipped a free forever [Community GitHub Action]( targeting this type of supply chain attacks. It issues AWS and SSH canary credentials (honeytokens) in your workflows and any attempted use would alert you and pinpoint exactly which workflow run has been compromised. Our action's code is open source and we will keep it that way. We wrote up a PoC reproducing TeamPCP's attack chain (Trivy, KICS, LiteLLM, Telnyx; [here]( and [this is Wiz's article]( that encourages the use of honeytokens when preventions fail in package security. You can register for free at and install the Tracebit GitHub App which helps monitor your workflow coverage and install our GitHub Action. After installation, you can click deploy on a reposi…
No pledges yet. Be the first to back this.
Comments
Similar requests
Show number of credentials per folder and overall dashboard stats
1 vote · 0 comments
[FEATURE] Decoy Vault
1 vote · 0 comments
Standardized API for automated unattended credentials/passwords change/renewal
1 vote · 0 comments
Seperate Image for Webvault
1 vote · 0 comments
Support SPIFFE authentication for M2M scenario
2 votes · 0 comments
No comments yet.