| ChainDrop poisoned hundreds of npm packages while retaining valid provenance. Learn why signed builds need source governance, policy gates, and runtime evidence. | Blog |
ChainDrop npm Worm: Why Valid SLSA Provenance Was Not Enough
calendar_today
August 10, 2026
domain
harness