{
  "slug": "human-signed-publish",
  "title": "Sigstore signs the build. Who signed the decision to publish?",
  "summary": "A phished credential published hundreds of npm packages and no human decided any of it. Provenance proves the pipeline. The worm has a pipeline.",
  "lede": "The software supply chain has excellent machine provenance and almost no human provenance. Sigstore and SLSA prove which pipeline built an artifact from which commit, which is real and valuable. Neither answers the question a self replicating worm exploits: did a person decide to release this version?",
  "date": "2026-09-05",
  "reading_time": "12 min read",
  "category": "Standards",
  "tags": [
    "supply chain security",
    "npm",
    "Sigstore",
    "provenance",
    "Shai-Hulud",
    "package registries",
    "SLSA"
  ],
  "image": "https://cdn.twc.sh/images/igcache/Human%20Signed%20Publish/1200_630/blog.jpg",
  "url": "/blog/human-signed-publish.html",
  "wordcount": 3064,
  "related": [
    "session-theft-aitm",
    "my-agent-shipped-this",
    "identity-failure-map"
  ],
  "schema": "Article"
}