Threat actors abused trusted Trivy distribution channels to inject credential‑stealing malware into CI/CD pipelines worldwide ...
# "local-vllm" → 127.0.0.1:8000 (no auth — local backend) # Failover: gpt-4o prefers OpenAI, falls back to Azure. # Each provider's auth format is driven by the profile type. # The actual key comes ...