<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cosign on PlumePHP</title><link>https://plumephp.com/tags/cosign/</link><description>Recent content in Cosign on PlumePHP</description><generator>Hugo</generator><language>zh-CN</language><lastBuildDate>Thu, 13 Aug 2026 10:00:00 +0800</lastBuildDate><atom:link href="https://plumephp.com/tags/cosign/index.xml" rel="self" type="application/rss+xml"/><item><title>软件供应链安全</title><link>https://plumephp.com/security-supply-chain/</link><pubDate>Thu, 13 Aug 2026 10:00:00 +0800</pubDate><guid>https://plumephp.com/security-supply-chain/</guid><description>&lt;h2 id="开篇供应链软件安全的阿喀琉斯之踵"&gt;开篇：供应链——软件安全的阿喀琉斯之踵&lt;/h2&gt;
&lt;p&gt;2020 年 SolarWinds Orion 供应链攻击震惊了全球网络安全界：攻击者通过篡改 SolarWinds 的构建系统，在 Orion 软件更新中植入后门 SUNBURST，影响了包括美国财政部、国土安全部在内的 18,000 多个组织。2021 年 Codecov Bash Uploader 被篡改，导致数千家企业的 CI 密钥泄露。这些事件揭示了一个残酷事实：&lt;strong&gt;即使你的代码完美无瑕，供应链上游的任何一个环节被攻陷，都可能让你成为受害者&lt;/strong&gt;。&lt;/p&gt;</description></item></channel></rss>