セキュリティと信頼 Jul 28, 2026 at 20:579ブックマークに追加

GitHubは、npmおよびGitHub Actionsにおける防御策の詳細を公開:署名付きパブリッシュ、強化されたトークン、強化された隔離。これは2025-2026年の攻撃ラッシュに対する直接の反撃策だ。
簡単に言えば - GitHubは、数か月間にわたる注目すべきサプライチェーン攻撃を受けて、npmとGitHub Actionsに一連のセキュリティ強化を導入しています。署名付き公開、厳格化されたトークン、ワークフローの隔離強化。怠惰なパイプラインには厳しい変更ですが、それだけの価値はあります。
npm + GitHub Actionsのチェーンは、JavaScriptのCI/CDの圧倒的なシェアを占めており、そのために保守者のトークン侵害などを通じた標的型攻撃の割合も増加しています。両プラットフォームの所有者であるGitHubは、2026年7月28日に「過去数か月で導入された変更」に関する振り返り記事を発表します。この動きは、より広範なアクセス強化の一環です(2026年9月2日から全てのコミッターに義務付けられる2FAもご参照ください - #1400)。
公式ブログ(github.blog/security)によると、防御策は3つの柱で構成されています:
Une attestation lie un artefact publié (paquet npm) à son processus de build - workflow, commit, environnement - de manière vérifiable côté consommateur. C'est la brique fondamentale du cadre SLSA (Supply-chain Levels for Software Artifacts) porté par la Linux Foundation.
具体的には、保守者は署名付きのGitHub Actionsワークフローから、検証可能な証明書付きでパッケージを公開できるようになりました。これにより、「リポジトリ外から署名されたパッケージをプッシュする」攻撃が防げます。パッケージと元のコミットのトレーサビリティが監査可能になります。
3つの重要なシグナルがあります。まず、攻撃対象がリポジトリからパイプラインにシフトしたことです。保守者のトークンやCIランナーを侵害すると、今ではソースコードへの直接アクセス以上の価値を得られます。次に、GitHubは段階的に変更を導入しています。新しいルールは旧モデルと共存し、段階的な移行で破壊的な変更はありません。最後に、支配的なプラットフォームが事実上の基準を押し付けています。GitLab、Bitbucket、Sonatypeのエコシステムは、企業の信頼性を維持するために追随するか、あるいは取り残されるかの選択を迫られています。
バックエンドリードへ:GitHub Actionsからのtrusted publishingを設定し、リリースワークフローで証明書を有効化してください。プラットフォームエンジニアへ:自己ホストランナーを確認してください。GitHubホスト型よりもセキュリティが緩いことが多いです。CISOへ:顧客から要求される前に、リリースパイプラインに証明書の検証を追加してください。
今後数か月でnpmの上位パッケージにおける証明書のカウント、強化後の最初の攻撃事例、PyPIやCargoが同じモデルに追随するかどうか。
本記事は人工知能により作成され、人間の編集管理のもとで校閲されています。
I hope these new security measures will be effective. The increase in supply-chain attacks is concerning.
I'm curious about the impact on small developers. Will these measures create barriers for those with limited resources?
GitHub might offer exemptions for open-source projects to ease the burden on small developers.
How will these new security measures affect the open-source community's collaborative spirit? Will it stifle innovation or foster safer development practices?
I wonder if these measures will be enough to stop the supply-chain attacks. The attackers are getting more sophisticated every day.
It's a constant arms race, but improved security measures can help tip the balance in our favor.
I'm glad to see GitHub taking proactive steps to secure npm and Actions. It's about time they addressed these vulnerabilities head-on.
I wonder how these new measures will affect the speed of development. Will they slow down the workflow for legitimate developers?
I'm curious about the impact on smaller projects. Will these new measures add unnecessary complexity for developers?
I'm curious about the impact on small developers. Will these measures make it harder for them to contribute to open-source projects?
I hope these new security measures will indeed make a difference. It's crucial for open-source platforms to stay ahead of these evolving threats.
Accès contrôlé aux modèles de pointe : habilitation, clés matérielles, juridictions