How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Why Are OSS Attackers Always After CI/CD Credentials?

calendar_today September 18, 2026 person alinskens@sonatype.com (Aaron Linskens) domain sonatype

CI/CD credentials are a prime target of malicious open source packages because of the sheer authority those credentials carry. Depending on their privileges, they can provide access to source code, build systems, package registries, cloud infrastructure, and production delivery.

open_in_new Read original post