sckit Supply Chain: npm Publish Without gitHead CI Provenance
Detects npm package publish events that lack 'gitHead' provenance metadata. The absence of this field indicates that the package was likely published from a developer's local machine rather than through an authorized CI/CD pipeline, a technique used in supply chain attacks to bypass CI-gated controls.
Sigma

