Not In My Git Yard: A Fuzzing-Based Defense Against Commit and Release Backdoors
A new paper proposes Lily, a tool that plugs backdoor detection into CI pipelines and release vetting workflows — aimed at the kind of supply-chain attack that's so far only been stopped by luck and manual review.
9 Sept 2026 · 3 min