GitHub Logs the Workflow Run, Not the Cache Write. That’s the Gap Cache Poisoning Lives In
The 2026 TanStack compromise (CVE-2026-45321) turned a bundle-size workflow into an npm publishing channel by poisoning a repo-scoped cache. The cache write left almost no runtime telemetry, which makes this a config audit before it’s ever a detection.