Browsing: CI/CD

A malware package advisory pipeline must preserve original evidence, verify provenance, identify affected versions, and issue auditable decisions. When an advisory is incorrect or withdrawn, create a correction event and switch the active snapshot instead of deleting history.

A self-hosted runner alone cannot keep CI/CD running during a GitHub outage. Prepare a source-code mirror, independent artifact repository, alternate build–test–deploy path, emergency credentials, and a verifiable failover and recovery runbook.