Skip to content

Conversation

@prasunsrivastav123-lang

This PR adds the polyfill.io incident as a real-world supply chain attack example to the Arabic A08 – Software and Data Integrity Failures section.

The example aligns with existing SolarWinds coverage and includes integrity verification guidance consistent with PCI DSS v4.0 requirements (6.4.3, 11.6.1).

Related to #812

@Neil-Smithline Neil-Smithline added the not-2025-critical Not required for 2025 release label Dec 24, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

not-2025-critical Not required for 2025 release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants