Incident Critical GitHub Actions docker-hub TeamPCP Part I: Twenty Days of Silent Access From a Two-Minute PR How a two-minute GitHub PR gave TeamPCP 18 days of silent access to Trivy's CI: Pwn Request, non-atomic rotation, and 82 poisoned Actions tags. Daniel Malvaceda · Mar 27, 2026 · 21 min read