The authors of “Not in My Git Yard” claim backdoors can be caught at commit and release time, potentially adding preventive checks to software supply-chain defenses.
state: expiredheat: lowuncertainty: highconvergesscott: mediumsoftware-supply-chain backdoor-detection security-tools
What is this?
“Not In My Git Yard: Catching Backdoors at Commit and Release Time” is a research paper describing a backdoor-detection tool called Lily for commit and release vetting. Its authors report experiments across hundreds of benign and backdoored commits and releases, claiming high detection accuracy with few false positives; the PDF snippet emphasizes automation under CI and release-pipeline time constraints. The supplied snippets do not identify the authors or establish Lily’s methods, numerical results, runtime, availability, or effectiveness in production.
Why it matters to Scott
Lily’s reported commit/release backdoor checks independently converge with Scott’s pre-release verification approach and offer a concrete candidate to investigate for Superlever’s publication pipeline and the WordPress Security Review’s versioned plugin vetting. The supplied radar hits track related dependency checks, not Lily itself; missing methods, runtime, availability and independently verified results prevent concluding that it could serve as a binding release gate.
dev:project.superleverdev:project.wordpress-security-reviewdev:concept.validated-release-preview-boundaryradar:kenwea-npm-install-sandboxradar:concept.software-supply-chain
queries asked of Scott's wikis
- coding-agent commits security review trust boundaries
- CI release gates automated security checks
- dependency vetting software supply-chain trust
- backdoor detection false positives evaluation
- agent harness verification before merge
Measured heat
no measured readings yet — the hourly heat pass fills this in
How the heat travelled
no chain yet — the hourly chain pass fills this in
Evidence (2) — ⭐ canonical anchor
Interpretation history
2026-09-11T04:26:44Z
The review horizon passed without methods, results, tool access, or independent validation, leaving this a paper-review lead rather than a demonstrated release-verification option. Expire for inactivity, not because the detection claim has been disproved; substantive technical evidence could reopen it.
2026-09-09T03:25:57Z
No substantive evidence has arrived to turn Lily’s reported research claims into a usable release-verification option. The paper remains a candidate for review, but the linked story and reconstructed paper echo are not independent validation of effectiveness or deployability.
2026-09-09T03:25:12Z
grounded: converges/medium — Lily’s reported commit/release backdoor checks independently converge with Scott’s pre-release verification approach and offer a concrete candidate to investiga
2026-09-09T03:22:48Z
case created — A concrete security paper establishes a distinct detection episode, but title-only evidence supports neither practical effectiveness nor urgency.
Decision trace
- 09-11 14:26expireThe review horizon passed without methods, results, tool access, or independent validation, leaving this a paper-review lead rather than a demonstrated release-verification option. Expire for inactivi
- 09-11 14:26alert_silentThe staleness trigger adds no consequential evidence or engineering action for Scott. No specific confirmation is expected within six hours, and there is no reason to interrupt the next briefing.
- 09-11 14:26alert_routeThe staleness trigger adds no consequential evidence or engineering action for Scott. No specific confirmation is expected within six hours, and there is no reason to interrupt the next briefing.
- 09-09 13:25repriceNo substantive evidence has arrived to turn Lily’s reported research claims into a usable release-verification option. The paper remains a candidate for review, but the linked story and reconstructed
- 09-09 13:25alert_silentNo new tool availability, validated result, or actionable supply-chain finding is established. Paper review can wait for the next briefing; no specific confirming fact is expected within six hours.
- 09-09 13:25alert_routeNo new tool availability, validated result, or actionable supply-chain finding is established. Paper review can wait for the next briefing; no specific confirming fact is expected within six hours.
- 09-09 13:25alert_silentThe supplied evidence identifies a paper about commit- and release-time backdoor detection but provides no methods, results, usable tool, or concrete vulnerability discovery. The topic fits Scott’s re
- 09-09 13:25alert_routeThe supplied evidence identifies a paper about commit- and release-time backdoor detection but provides no methods, results, usable tool, or concrete vulnerability discovery. The topic fits Scott’s re
- 09-09 13:25groundLily’s reported commit/release backdoor checks independently converge with Scott’s pre-release verification approach and offer a concrete candidate to investigate for Superlever’s publication pipeline
- 09-09 13:22createA concrete security paper establishes a distinct detection episode, but title-only evidence supports neither practical effectiveness nor urgency.