Decision RecordActivePublished without chair review

Use scoped supply-chain change control instead of a blanket engineering freeze

Software supply-chain change control

Reader challenge

Challenge this conclusion

Contest a specific conclusion. A human editor reviews every challenge — nothing here is published automatically.

Security check loading…
Confidence
High
Section support
High confidence · 0/9 backed · 2 gaps · panel
Severity
Severity was not recorded when this record was first published.
Freshness · v1
Last updated 46 days ago
Last revised 2026-07-04
Active6 evidence references · Published 04 Jul 2026 · Daily RoundtableServer-rendered freshness may trail the latest update by the page cache window.
Current position

Do not freeze all engineering. Temporarily gate new npm or Composer dependencies, risky dependency upgrades, GitHub Actions workflow edits, Composer tag consumption, CI jobs executing third-party install scripts, package-publishing tokens, and suspicious dependency installs.

Public guidance

Current public guidance · the full record

Current public value version · v1
01

What to do now

Under reviewAt a glance

Do not freeze all engineering.

Immediately require approval for supply-chain trust-boundary changes: adding new npm dependencies, adding new Composer dependencies, dependency upgrades that change maintainer or install-script risk, GitHub Actions workflow edits, Composer tag pulls, CI jobs that run third-party install scripts or third-party actions, and package-publishing token changes.

Review recent CI and package activity for those same categories. Rotate package-publishing tokens and related CI secrets where suspicious installs, suspicious dependency upgrades, or suspicious workflow changes occurred.

Keep campaign names and attribution out of operational criteria unless primary package or campaign evidence is added; use observable changes in npm, Composer, GitHub Actions, CI execution, and token exposure as the trigger.

02

Why now

Under review

On 2026-07-04, the packet presented a dense set of software supply-chain signals in the same operational lane: North Korea-linked npm packages mimicking Rollup polyfills to steal developer secrets, Shadow Code malicious NPM packages targeting developers, GhostAction GitHub Actions workflow compromise, IronWorm npm supply-chain activity targeting Arweave and WeaveDB developers, and Megalodon GitHub Actions intrusion compromising Laravel-Lang Composer packages.

That density supports a temporary gate around trust-boundary changes now. It does not support a blanket engineering freeze because the cited support is about specific trust boundaries, not all engineering work.

03

Who is affected

Under review

Developer teams adding or upgrading npm dependencies are affected because the packet reports North Korea-linked npm packages mimicking Rollup polyfills to steal developer secrets, Shadow Code malicious NPM packages targeting developers, and IronWorm npm supply-chain activity targeting Arweave and WeaveDB developers.

Developer teams adding or upgrading Composer dependencies are affected because the selected control includes Composer dependencies and Composer tag consumption, and the packet reports Megalodon GitHub Actions intrusion compromising Laravel-Lang Composer packages.

Repository owners and platform teams changing GitHub Actions workflows are affected because GhostAction is described as a GitHub Actions workflow compromise campaign and Megalodon is described as a GitHub Actions intrusion.

CI/CD operators are affected when jobs execute third-party install scripts, third-party actions, npm package code, or Composer package code, because the selected control treats those execution paths as trust-boundary crossings.

Owners of package-publishing tokens and CI secrets are affected because the roundtable focused on developer-secret theft, package-publishing token risk, and token rotation after suspicious installs or workflow changes.

04

What supports this

Under review

The supply-chain analyst’s interaction supports the action by explicitly saying today does not justify a blanket engineering freeze and does justify a scoped freeze on new npm packages, dependency upgrades, GitHub Actions workflow edits, Composer tag consumption, and CI jobs executing install scripts or third-party actions.

The moderator’s interaction supports the action by restating the narrower response: gate new npm and Composer dependencies, dependency upgrades that change maintainer or install-script risk, GitHub Actions workflow edits, and CI paths that execute third-party code.

The final synthesis supports the principle behind the action by saying the panel consensus was not to “patch everything,” but to contain and invalidate trust where exploitation or token theft is plausible.

The handoff summary for North Korea-linked npm packages supports the npm and developer-secret part of the scope by reporting packages mimicking Rollup polyfills to steal developer secrets.

The Shadow Code handoff summary supports the developer-targeted npm portion by reporting malicious NPM packages targeting developers.

The GhostAction handoff summary supports the GitHub Actions portion by reporting a GitHub Actions workflow compromise campaign.

The IronWorm handoff summary supports the npm supply-chain portion by reporting an npm supply-chain worm targeting Arweave and WeaveDB developers.

The Megalodon handoff summary supports the Composer and GitHub Actions portion by reporting a GitHub Actions intrusion compromising Laravel-Lang Composer packages.

The evidence auditor supports the scoped operational decision and separately flags that named campaign details should not be expanded into package/version or blast-radius claims without stronger sources.

05

How the Roundtable reached this

Under review

The supply-chain analyst rejected a blanket engineering freeze and narrowed the response to a scoped freeze on trust-boundary changes: new npm packages, dependency upgrades, GitHub Actions workflow edits, Composer tag consumption, and CI jobs that execute install scripts or third-party actions.

The moderator accepted that separation between “move immediately” and “do not overreact,” adding Composer dependencies, dependency upgrades that alter maintainer or install-script risk, GitHub Actions workflow edits, and CI paths that execute third-party code.

The evidence auditor supported the scoped gate, while marking GhostAction, IronWorm, Megalodon, and North Korea-linked attribution as contextual because the packet lacks primary package artifacts, affected package/version details, authoritative campaign reports, and stronger attribution corroboration.

The arbiter selected the operational-action record with that boundary: use scoped supply-chain change control, not a blanket freeze.

06

What is uncertain

Missing

The strongest uncertainty is scope detail, not whether to gate.

The packet supports gating npm, Composer, GitHub Actions, CI third-party code execution, and package-publishing tokens, but it does not prove which specific package versions or repositories are affected.

GhostAction, IronWorm, and Megalodon are present as packet-described examples, not as fully evidenced package-level cases. North Korea-linked activity is usable as reported context with moderate attribution confidence, but not as a definitive attribution basis for the operational control.

07

What evidence is missing

Missing

The packet does not include primary npm package artifacts, Composer package artifacts, affected package names, affected versions, install-script samples, workflow files, registry telemetry, or authoritative campaign reports for GhostAction, IronWorm, or Megalodon.

It also does not include corroborating attribution sources strong enough to turn North Korea-linked crypto theft, malicious npm packages, Drift, KelpDAO, and developer-targeting npm activity into one confirmed campaign claim.

Those gaps do not block the scoped gate, but they do block public claims about exact package blast radius, exact affected versions, or definitive actor attribution.

08

What would change this

Under review

Escalate from a scoped gate toward a broader engineering freeze only if evidence shows widespread execution of malicious dependency code across many repositories, active compromise of shared CI infrastructure, or repeated unauthorized package-publishing token use that cannot be contained repository by repository.

Narrow the gate if reviews show no suspicious installs, no risky dependency upgrades, no unauthorized GitHub Actions workflow edits, no suspicious Composer tag pulls, and no exposed package-publishing tokens.

Strengthen public attribution only if corroborating sources support more than the current reported or moderate North Korea-linked framing.

09

What to watch next

Under review

Watch for proof of what code ran where: CI job logs that executed third-party install scripts or third-party actions, GitHub Actions workflow edits, npm and Composer dependency additions, Composer tag pulls, package-publishing token use, and SBOM deltas.

If those reviews find suspicious installs or workflow changes, rotate affected package-publishing tokens and CI secrets.

If authoritative package reports or primary artifacts identify specific npm packages, Composer packages, versions, repositories, or compromised workflows, replace the broad trust-boundary gate with targeted blocks, removals, and token rotations for those named items.

Sources & context

Evidence basis

6 references
Context
The room now has a cleaner separation between “move immediately” and “do not overreact.” Tomas narrowed the supply-chain…

The room now has a cleaner separation between “move immediately” and “do not overreact.” Tomas narrowed the supply-chain response from a broad engineering freeze to a scoped freeze around trust-boundary changes: new npm and Composer depende…

Observed 4 Jul 2026
Context
No, Halil — today does **not** justify a blanket engineering freeze. It does justify a **scoped freeze on trust-boundary…

No, Halil — today does **not** justify a blanket engineering freeze. It does justify a **scoped freeze on trust-boundary changes**: new npm packages, dependency upgrades, GitHub Actions workflow edits, Composer tag consumption, and any CI j…

Observed 4 Jul 2026
Context
Summary: This is a busy, high-pressure morning, but the panel’s consensus is not “patch everything”; it is “contain and …

Summary: This is a busy, high-pressure morning, but the panel’s consensus is not “patch everything”; it is “contain and invalidate trust first where exploitation or token theft is plausible.” Exposed Citrix NetScaler, Oracle PeopleSoft, Cis…

Observed 4 Jul 2026
Context
Memory chunk
Observed 4 Jul 2026
Context
Memory chunk
Observed 4 Jul 2026
Revision trail

Public value history

1 event on record
1 value version · 1 update · 0 predictions
  1. 04 Jul 2026Initial public guidanceCurrent guidance

    Created the first public value version for this Decision Record.

Unified Search

Search the public record.