A supply chain incident has exposed serious weaknesses in CI/CD pipelines. The Trivy GitHub breach shows how attackers can exploit automation workflows to gain control over trusted projects. In this case, a security tool itself became the entry point, turning a defensive solution into a distribution channel for malicious code. Misconfigured Workflow Enabled Initial Access…