# Sponsored: Understanding CI/CD attack paths Page: https://stenobird.com/podcast/risky-bulletin-5423259/sponsored-understanding-ci-cd-attack-paths Text version: https://stenobird.com/podcast/risky-bulletin-5423259/sponsored-understanding-ci-cd-attack-paths.md Podcast: [Risky Bulletin](https://stenobird.com/podcast/risky-bulletin-5423259) Published: 2026-06-12T04:28:07+00:00 Episode link: https://risky.biz/RBNEWSSI131/ Audio file: https://dts.podtrac.com/redirect.mp3/media3.risky.biz/RBNEWSSI131.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/risky-bulletin-5423259/episodes/sponsored-understanding-ci-cd-attack-paths Duration seconds: 948 ## Resource In this sponsored episode, James Wilson chats with SpecterOps CTO Jared Atkinson about the central role that GitHub has played in recent supply chain compromises. GitHub is where code gets built, tested, and shipped to devices, cloud, and on-prem environments. Understanding the paths an attacker can use to get into GitHub, and where they can pivot to from there, is essential to securing your GitHub repos and CI/CD pipelines. ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/risky-bulletin-5423259/episodes/sponsored-understanding-ci-cd-attack-paths/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/risky-bulletin-5423259/sponsored-understanding-ci-cd-attack-paths.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.