<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Happyberg Engineering</title><description>Long-form analyses of supply-chain attacks, infrastructure, and the defenses that hold. By the engineers at Happyberg Labs.</description><link>https://happyberg.com/</link><language>en-us</language><item><title>TanStack and the day provenance attestation stopped being a defense</title><link>https://happyberg.com/blog/tanstack-mini-shai-hulud/</link><guid isPermaLink="true">https://happyberg.com/blog/tanstack-mini-shai-hulud/</guid><description>On May 11, 2026, malicious npm artifacts were signed by TanStack&apos;s legitimate OIDC pipeline. Sigstore verified them. Every signature check we built for this case returned green. Here is what happened, what failed, and the one defense that still works.</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate><category>supply-chain</category><category>npm</category><category>shai-hulud</category><category>tanstack</category><category>provenance</category><category>release-age</category></item></channel></rss>