Thompson’s idea can be applied to CI systems Your CI system can be malicious even if the source code is clean of malicious code Self-reproduction allow long-term compromise Initial infection is feasible in practice: malicious commit, dependency confusion, registry compromise, etc