Robuta

Sponsor of the Day: Jerkmate
https://bdtechtalks.com/2026/04/27/claude-code-api-token-leak/ Claude Code is leaking API keys into public package registries - TechTalks Apr 27, 2026 - A new study reveals how AI coding assistants like Claude Code are quietly hoarding and publishing sensitive API keys to code repositories. claude codeapi keyspublic packageleakingregistries https://repos.openssf.org/build-provenance-for-all-package-registries Build Provenance for All Package Registries | wg-securing-software-repos OpenSSF Working Group on Securing Software Repositories package registriessecuring softwarebuildprovenancewg https://buildkite.com/platform/package-registries/ Buildkite Package Registries | Speed up builds, lock down security | Buildkite Start improving your software supply chain today. Eliminate bottlenecks with co-located packages for faster builds and deployments across any ecosystem. package registriesbuildkitespeedbuildslock