Entries by Julia Choe

Behavioral Risk Brief: SleeperGem

The Claim Governance frameworks that treat package name recognition and maintainer history as ongoing proof of safety create systemic risk when a compromised artifact can behave differently depending on where it executes. Zero Trust for Code addresses this by requiring a pre-execution trust decision on what a package will do in a specific environment, rather […]

Behavioral Risk Brief: Ghostcommit

The Claim Governance frameworks that treat automated code review as sufficient validation create systemic risk when trust is granted based on what a scanner can see rather than what an artifact will do once an agent acts on it. Zero Trust for Code addresses this by requiring a pre-execution trust decision on what a merged […]