<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xml:base="https://countersign.dev/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    
    <title>Countersign — Teardowns &amp; Advisories</title>
    <link>https://countersign.dev/</link>
    <atom:link href="https://countersign.dev/feed.xml" rel="self" type="application/rss+xml" />
    <description>Independent configuration teardowns and security advisories.</description>
    <language>en</language>
    <item>
      <title>Pipeline Teardown — [redacted client] · GitHub Actions</title>
      <link>https://countersign.dev/teardowns/sample-teardown/</link><description>Five findings, two of them load-bearing: a yanked, unpinned action that a general LLM will wave through, and a secret referenced three ways that will break a 3am deploy on the next rotation.</description>
      <content:encoded></content:encoded><pubDate>Thu, 04 Jun 2026 17:00:00 -0700</pubDate>
      <dc:creator>Paul Julius</dc:creator>
      <guid>https://countersign.dev/teardowns/sample-teardown/</guid>
    </item>
    <item>
      <title>Advisory: GitHub Actions moving-tag pin drift</title>
      <link>https://countersign.dev/advisories/actions-checkout-pin-drift/</link><description>Moving GitHub Actions tags remain convenient, but they keep supply-chain authority outside your repository. Pin critical workflow actions to full commit SHAs and record the human-readable version beside the pin.</description>
      <content:encoded></content:encoded><pubDate>Mon, 08 Jun 2026 17:00:00 -0700</pubDate>
      <dc:creator>Paul Julius</dc:creator>
      <guid>https://countersign.dev/advisories/actions-checkout-pin-drift/</guid>
    </item>
  </channel>
</rss>