Squeezing the Balloon: Why Securing the Open Source Build Process is Only the Beginning
We finally killed the long-lived developer API key, a massive victory for open-source security. But as NDSS 2026 and USENIX Enigma '25 revealed, attackers haven't given up—they've just moved to our build pipelines and flooded our vulnerability data. Here is what we must do next.