# Execution Pipelines Function as Control Planes Without Verification Primitives Capable of Validating the Authority They Execute

- **Artifact ID:** CHQ-P-2026-015
- **Version:** v1.4
- **Status:** ACTIVE
- **Public record:** https://record.cybersecurityhq.com/positions/chq-p-2026-015
- **Machine-record SHA-256:** `b2dbdfa7488f1d5000fdeff220430356fd14e947c926cfff4381e10d466185d6`

## Canonical text

```text
[SECTION] POSITION METADATA
POSITION_ID=CHQ-P-2026-015
VERSION=v1.4
STATUS=ACTIVE
EFFECTIVE=2026-09-22
TITLE=Execution Pipelines Function as Control Planes Without Verification Primitives Capable of Validating the Authority They Execute
DOCTRINE_FAMILY=EXECUTION_GOVERNANCE
ASSUMPTION_INVALIDATED=EXECUTION_AUTHORITY_INHERITANCE
PRESSURE_CLASS=STRUCTURAL
POSITION_TYPE=STRUCTURAL_CONDITION
SIGNAL_COUNT=6
DURABILITY_CLASS=STRUCTURAL
EVIDENCE_STATE=CONFIRMED
VECTOR_COUNT=6
LENS=LENS-001
PATTERN_REGISTER_ID=CHQ-PR-015
SOURCE_SIGNALS=SN-2026-03-19-01, SN-2026-03-20-01, SN-2026-03-23-01, SN-2026-03-24-02, SN-2026-03-25-01, SN-2026-03-17-02
GOVERNING_CONSTRAINT=CHQ-ASC-2026-001, CHQ-ASC-2026-004
ESG_REFERENCE=CHQ-D-2026-ESG v1.0
REVISION_POLICY=Amendment only

[SECTION] AMENDMENT NOTE
AMENDMENT AMD-001 · JULY 24, 2026 · REINFORCEMENT
Window reinforcement recorded. The July 2026 npm publishing campaign executed through legitimate release pipelines whose OIDC identities carried publishing authority with no primitive validating that the authority was correctly held. Provenance verified continuity throughout; the pipelines executed compromised authority. Canonical evidence basis and counts are unchanged; the reinforcement is recorded at the evidence layer.

AMENDMENT AMD-2026-09-22-POSITION-RECORD-CORRECTIVE-WAVE · SEPTEMBER 22, 2026 · POSITION RECORD STANDARD CORRECTION. Canonical field semantics, evidence counts, identifiers, independence wording, and publication integrity corrected in one dated wave.

AMENDMENT CHQ-RAT-2026-001-CANONICAL-TEXT-EXECUTION-WAVE · SEPTEMBER 22, 2026 · CANONICAL TEXT EXECUTION. Scheduled prose constructions rewritten for grammatical clarity without changing the underlying judgment.

AMENDMENT AMD-002 · SEPTEMBER 22, 2026 · REINFORCEMENT
Window reinforcement recorded. In the operator-environment incident of 19 July 2026 (CHQ-EX-2026-025), agents used a path-traversal flaw in the artifact repository tier (CVE-2026-66384, entered in the federal exploited catalog on 27 August 2026) for egress and lateral movement. The artifact repository is an execution pipeline component whose authority was exercised by an actor it had no primitive to validate. The canonical evidence basis and counts are unchanged; the reinforcement is recorded at the evidence layer (CHQ-ED-2026-030). Related: CHQ-P-2026-017.

[SECTION] EVIDENCE BASIS
PRIMARY: The TeamPCP campaign (March 19–25, 2026) demonstrated execution authority inheritance across five ecosystems in six days.

Source SN-2026-03-19-01 (Wiz / Aqua Security): Trivy GitHub Actions Compromise. TeamPCP compromised Aqua Security's Trivy vulnerability scanner and associated GitHub Actions (trivy-action, setup-trivy). 75 of 76 version tags force-pushed to malicious payloads. Credential stealer exfiltrated SSH keys, cloud credentials, Kubernetes tokens, Docker registry credentials, npm tokens, and TLS private keys from every pipeline that ran the compromised action. GitHub Actions runners granted the compromised action full access to pipeline secrets as a design feature. No verification occurred between the tag reference and the code that executed.

Source SN-2026-03-20-01 (Aikido / Socket): GlassWorm Wave 3 / CanisterWorm, an npm ecosystem propagation campaign. Stolen npm tokens from Trivy pipeline compromise were used to publish malicious packages across 47+ npm packages. CanisterWorm deployed as self-propagating credential harvester using ICP blockchain canister as C2 dead drop. At no point did any system verify that the publishing entity was the legitimate maintainer.

Source SN-2026-03-23-01 (Checkmarx advisory): Checkmarx KICS GitHub Action Compromise. On March 23, 35 tags in the Checkmarx KICS GitHub Action were hijacked between 12:58–16:50 UTC. Identical credential stealer payload as the Trivy operation. Checkmarx AST Open VSX extensions also compromised. The stolen credentials from the Trivy compromise were sufficient to poison additional GitHub Actions in unrelated repositories. The same execution authority inheritance pattern repeated: tag reference → code execution → credential exfiltration → downstream poisoning.

Source SN-2026-03-24-02 (LiteLLM / PyPI record): LiteLLM PyPI Package Compromise. On March 24, malicious LiteLLM versions 1.82.7 and 1.82.8 published to PyPI. LiteLLM is an open-source LLM proxy present in 36% of cloud environments with approximately 480 million PyPI downloads, centralizing API credentials for over 100 LLM providers. LiteLLM's CI/CD pipeline ran Trivy as part of its build process. The compromised Trivy action exfiltrated the PYPI_PUBLISH token. LiteLLM is the clearest instantiation of the position's core claim: a build dependency inherited execution authority, used that authority to access distribution credentials, and published compromised artifacts to a production-facing registry. The CI/CD-to-runtime boundary did not function as a control surface.

Source SN-2026-03-25-01 (aggregate docket CHQ-ED-2026-015): Trivy-to-Ecosystem Credential Cascade. The aggregate cascade across five ecosystems (GitHub Actions, Docker Hub, npm, Open VSX, PyPI) from March 19–25. Each stage of the cascade was enabled by execution authority inherited in the previous stage. No stage required a new exploit. Each stage required only that the next system treat distribution as authorization.
SUPPORTING: SN-2026-03-17-02 (reinforcing): Langflow CVE-2026-33017, an AI platform exploited within hours of advisory publication. Attackers targeted accumulated execution authority: API keys for LLM providers, cloud credentials, and database connections held by the platform as a byproduct of its integration function. Langflow's design aggregates credentials from multiple external services into a single execution context. This is the same structural condition as LiteLLM but at the application layer rather than the build layer. Both demonstrate that execution authority aggregation creates high-leverage targets regardless of the system's intended function.
SUPPORTING: SN-2026-03-19-01 / CHQ-EX-2026-009: Trivy and GitHub Actions tag compromise.
SUPPORTING: SN-2026-03-20-01 / CHQ-EX-2026-009: GlassWorm and CanisterWorm registry propagation.
SUPPORTING: SN-2026-03-23-01 / CHQ-EX-2026-012: Checkmarx KICS tag hijacking.
SUPPORTING: SN-2026-03-24-02 / CHQ-EX-2026-013: LiteLLM package compromise and credential exposure.
SUPPORTING: SN-2026-03-25-01 / CHQ-EX-2026-013: aggregate Trivy-to-ecosystem cascade.
SUPPORTING: SN-2026-03-17-02 / CHQ-EX-2026-010: Langflow credential aggregation evidence.

[SECTION] AUTHORITY DERIVATION
No constraint derivation applies. This is a standalone Position.

[SECTION] GOVERNING CONSTRAINT
CHQ-ASC-2026-001
CHQ-ASC-2026-004

[SECTION] SCOPE OF APPLICATION
This Position applies to decisions involving software supply chain architecture, CI/CD pipeline security governance, package registry trust models, build system credential management, and software distribution integrity.

It applies wherever execution pipelines consume external dependencies without independently verifying the authority of the executing code at runtime. This describes the dominant architecture of software build and distribution systems.

It does not evaluate specific CI/CD platforms, specific registry implementations, or specific build tool configurations.

[SECTION] POSITION STATEMENT
Execution pipelines now function as control planes. They do not contain verification primitives capable of validating the authority they execute.
Any system that executes external code inherits its authority unless it can independently verify that authority at execution time. No widely deployed execution pipeline in the current software ecosystem performs this verification.

The structural condition is a mismatch between control and verification. Execution pipelines determine what code runs in production environments, what credentials are accessible during build and deployment, and what artifacts are published to distribution channels. These are control plane functions. They are exercised without control plane governance.

Distribution is treated as trust. A package published to a registry is treated as authorized to execute. A GitHub Action referenced by tag is treated as authorized to access pipeline secrets. A CI/CD dependency is treated as authorized to inherit the build environment's credentials. In each case, the authorization decision is not made. It is assumed from the act of distribution.

The system cannot distinguish between receiving a package and granting it control.

[SECTION] STRUCTURAL OBSERVATION
Together with CHQ-P-2026-014 (Management Plane Deterministic Control), this Position establishes that control plane authority exists in two locations the traditional security model does not govern: management infrastructure and execution pipelines. P-014 describes control plane authority in systems designed to manage. P-015 describes control plane authority in systems designed to build and distribute. Both exercise authority without verification at the point of execution.

CHQ-P-2026-013 (Portable Developer Identity): Developer identity portability is the propagation mechanism that execution authority inheritance exploits. P-013 establishes that portable identity means portable compromise. P-015 establishes the structural reason: portable identity carries portable execution authority, and no system verifies that authority at the point of use.

CHQ-P-2026-011 (Tool Presence ≠ Functioning Control): Trivy was deployed as a security scanner. Its presence in CI/CD pipelines was evidence of security practice. Its compromise converted that presence into an attack vector. P-011's claim is directly instantiated.

CHQ-P-2026-002 (Verification Collapse): P-015 identifies a specific domain where verification collapse is structural. Execution pipelines are the domain in which the verification primitive that would prevent inherited authority exploitation does not exist at scale.

[SECTION] ARCHITECTURAL IMPLICATION
Execution pipelines exercise three control plane functions without control plane governance:

Code selection. Pipelines determine which code executes in the build and deployment environment. The selection is based on references (tags, version numbers, package names) that can be mutated without detection.

Credential exposure. Pipelines expose credentials to executing code as a design feature. Build secrets, publish tokens, cloud credentials, and API keys are available to any code that executes in the pipeline context. The credential boundary is the execution boundary. There is no intermediate verification layer.

Distribution authority. Pipelines publish artifacts to registries, container repositories, and package managers. Publication authority is inherited from pipeline credentials, not independently granted. A compromised pipeline publishes with the same authority as a legitimate one.

A-031 (Credential compromise within a registry produces damage bounded by that registry's scope) is retired on issuance. A single credential theft in one registry produced authenticated actions across four additional registries within days. Registry scope is not a containment boundary. It is a propagation surface.

A-033 (Software distribution channels are passive delivery mechanisms that do not exercise execution authority) is under pressure on issuance. Registries, package managers, and CI/CD pipelines are governed as delivery infrastructure. P-015 establishes they function as control planes. They determine what code executes, what credentials are exposed, and what artifacts are published.

A-032 (Management plane authority bounded by identity enforcement) is under additional pressure. Execution pipelines exercise management-plane-equivalent authority without passing through identity enforcement.

A-021 (Security authority persists through delegation chains) is under additional pressure. Execution pipelines delegate authority through dependency resolution, action references, and build tool invocation. None of these delegation points verify that the delegated authority is still valid or that the delegatee is the expected entity.

A-020 (Control plane integrity can be verified independently of data plane activity) is under additional pressure. Execution pipelines are a control plane whose integrity cannot be verified from outside the pipeline.

[SECTION] EVIDENTIAL RECORD
TITLE=CybersecurityHQ Execution Pipeline Authority Evidence
DOCKET=CHQ-ED-2026-015
EXHIBITS=CHQ-EX-2026-009, CHQ-EX-2026-010, CHQ-EX-2026-012, CHQ-EX-2026-013
SIGNALS=SN-2026-03-19-01, SN-2026-03-20-01, SN-2026-03-23-01, SN-2026-03-24-02, SN-2026-03-25-01, SN-2026-03-17-02

[SECTION] STRUCTURAL CONSEQUENCE
The structural consequence is universal across the software ecosystem. It is not specific to any language, registry, CI/CD platform, or deployment target. It is a property of how execution authority is granted: implicitly, through distribution, without verification.

Systems responsible for authorization can execute inherited authority from compromised execution pipelines, even where internal control design is otherwise sound. Authorization systems are built and deployed through the same execution pipelines as every other software component. They inherit the same unverified authority.

The position's force reduces in environments where every execution step independently verifies the authority of the code it runs: reproducible builds from source with cryptographic attestation, hardware-rooted signing of every artifact at every stage, runtime verification of provenance before credential exposure. These environments exist in theory. None are widely deployed at ecosystem scale.

[SECTION] BOUNDARY OF APPLICATION
Prescriptive pipeline hardening guidance
Specific dependency pinning recommendations
Vendor-specific CI/CD security configurations
Regulatory compliance requirements for software supply chain governance

[SECTION] SUGGESTED CITATION
CybersecurityHQ Position
"Execution Pipelines Function as Control Planes Without Verification Primitives Capable of Validating the Authority They Execute"
CHQ-P-2026-015
Version 1.4
2026-09-22

[SECTION] POSITION STATUS
STATUS=ACTIVE
VERSION=v1.4

[SECTION] RECORD INTEGRITY
SCOPE=PRS-03.1 CANONICAL TEXT (NOT RENDERING)
VERSION=v1.4

[SECTION] DOCTRINAL ALIGNMENT
Standalone Position

[SECTION] REFERENCE CONDITIONS
Authored independently of any subscribing organization
Not tailored to a specific contractual, commercial, or advocacy interest
Subsequent analysis based only on new evidence

[SECTION] LINKED CONDITIONS

[SECTION] LINKED ASSUMPTIONS
```

## Complete structured record

```json
{
  "id": "CHQ-P-2026-015",
  "title": "Execution Pipelines Function as Control Planes Without Verification Primitives Capable of Validating the Authority They Execute",
  "status": "ACTIVE",
  "version": "v1.4",
  "snapshot_date": "2026-09-22",
  "doctrine_family": "EXECUTION_GOVERNANCE",
  "assumption_class": "EXECUTION_AUTHORITY_INHERITANCE",
  "pressure_class": "STRUCTURAL",
  "position_type": "STRUCTURAL_CONDITION",
  "signal_count": 6,
  "pattern_register_id": "CHQ-PR-015",
  "durability_class": "STRUCTURAL",
  "evidence_state": "CONFIRMED",
  "vector_count": 6,
  "lens": "LENS-001",
  "source_signals": [
    "SN-2026-03-19-01",
    "SN-2026-03-20-01",
    "SN-2026-03-23-01",
    "SN-2026-03-24-02",
    "SN-2026-03-25-01",
    "SN-2026-03-17-02"
  ],
  "governing_acj": [
    "CHQ-ASC-2026-001",
    "CHQ-ASC-2026-004"
  ],
  "evidence_docket": "CHQ-ED-2026-015",
  "evidence_dockets": [
    {
      "docket": "CHQ-ED-2026-015",
      "issue_date": "2026-03-25",
      "position_version": "v1.0",
      "relationship": "SUPERSEDED"
    },
    {
      "docket": "CHQ-ED-2026-018",
      "issue_date": "2026-05-04",
      "position_version": "v1.0",
      "relationship": "SUCCESSOR"
    },
    {
      "docket": "CHQ-ED-2026-023",
      "issue_date": "2026-07-24",
      "position_version": "v1.1",
      "relationship": "AMENDMENT"
    },
    {
      "docket": "CHQ-ED-2026-030",
      "issue_date": "2026-09-22",
      "issued": "2026-09-22",
      "position_version": "v1.4",
      "relationship": "AMENDMENT"
    }
  ],
  "prior_evidence_dockets": [
    {
      "docket": "CHQ-ED-2026-018",
      "relationship": "SUCCESSOR",
      "position_version": "v1.0"
    },
    {
      "docket": "CHQ-ED-2026-023",
      "relationship": "AMENDMENT",
      "position_version": "v1.1"
    }
  ],
  "extends_position": null,
  "doctrine_statement": "Execution pipelines now function as control planes. They do not contain verification primitives capable of validating the authority they execute.",
  "evidence_basis": {
    "primary": "The TeamPCP campaign (March 19–25, 2026) demonstrated execution authority inheritance across five ecosystems in six days.\n\nSource SN-2026-03-19-01 (Wiz / Aqua Security): Trivy GitHub Actions Compromise. TeamPCP compromised Aqua Security's Trivy vulnerability scanner and associated GitHub Actions (trivy-action, setup-trivy). 75 of 76 version tags force-pushed to malicious payloads. Credential stealer exfiltrated SSH keys, cloud credentials, Kubernetes tokens, Docker registry credentials, npm tokens, and TLS private keys from every pipeline that ran the compromised action. GitHub Actions runners granted the compromised action full access to pipeline secrets as a design feature. No verification occurred between the tag reference and the code that executed.\n\nSource SN-2026-03-20-01 (Aikido / Socket): GlassWorm Wave 3 / CanisterWorm, an npm ecosystem propagation campaign. Stolen npm tokens from Trivy pipeline compromise were used to publish malicious packages across 47+ npm packages. CanisterWorm deployed as self-propagating credential harvester using ICP blockchain canister as C2 dead drop. At no point did any system verify that the publishing entity was the legitimate maintainer.\n\nSource SN-2026-03-23-01 (Checkmarx advisory): Checkmarx KICS GitHub Action Compromise. On March 23, 35 tags in the Checkmarx KICS GitHub Action were hijacked between 12:58–16:50 UTC. Identical credential stealer payload as the Trivy operation. Checkmarx AST Open VSX extensions also compromised. The stolen credentials from the Trivy compromise were sufficient to poison additional GitHub Actions in unrelated repositories. The same execution authority inheritance pattern repeated: tag reference → code execution → credential exfiltration → downstream poisoning.\n\nSource SN-2026-03-24-02 (LiteLLM / PyPI record): LiteLLM PyPI Package Compromise. On March 24, malicious LiteLLM versions 1.82.7 and 1.82.8 published to PyPI. LiteLLM is an open-source LLM proxy present in 36% of cloud environments with approximately 480 million PyPI downloads, centralizing API credentials for over 100 LLM providers. LiteLLM's CI/CD pipeline ran Trivy as part of its build process. The compromised Trivy action exfiltrated the PYPI_PUBLISH token. LiteLLM is the clearest instantiation of the position's core claim: a build dependency inherited execution authority, used that authority to access distribution credentials, and published compromised artifacts to a production-facing registry. The CI/CD-to-runtime boundary did not function as a control surface.\n\nSource SN-2026-03-25-01 (aggregate docket CHQ-ED-2026-015): Trivy-to-Ecosystem Credential Cascade. The aggregate cascade across five ecosystems (GitHub Actions, Docker Hub, npm, Open VSX, PyPI) from March 19–25. Each stage of the cascade was enabled by execution authority inherited in the previous stage. No stage required a new exploit. Each stage required only that the next system treat distribution as authorization.",
    "supporting": [
      "SN-2026-03-17-02 (reinforcing): Langflow CVE-2026-33017, an AI platform exploited within hours of advisory publication. Attackers targeted accumulated execution authority: API keys for LLM providers, cloud credentials, and database connections held by the platform as a byproduct of its integration function. Langflow's design aggregates credentials from multiple external services into a single execution context. This is the same structural condition as LiteLLM but at the application layer rather than the build layer. Both demonstrate that execution authority aggregation creates high-leverage targets regardless of the system's intended function.",
      "SN-2026-03-19-01 / CHQ-EX-2026-009: Trivy and GitHub Actions tag compromise.",
      "SN-2026-03-20-01 / CHQ-EX-2026-009: GlassWorm and CanisterWorm registry propagation.",
      "SN-2026-03-23-01 / CHQ-EX-2026-012: Checkmarx KICS tag hijacking.",
      "SN-2026-03-24-02 / CHQ-EX-2026-013: LiteLLM package compromise and credential exposure.",
      "SN-2026-03-25-01 / CHQ-EX-2026-013: aggregate Trivy-to-ecosystem cascade.",
      "SN-2026-03-17-02 / CHQ-EX-2026-010: Langflow credential aggregation evidence."
    ]
  },
  "doctrinal_alignment": [],
  "revision_policy": "Amendment only",
  "esg_reference": "CHQ-D-2026-ESG v1.0",
  "scope": "This Position applies to decisions involving software supply chain architecture, CI/CD pipeline security governance, package registry trust models, build system credential management, and software distribution integrity.\n\nIt applies wherever execution pipelines consume external dependencies without independently verifying the authority of the executing code at runtime. This describes the dominant architecture of software build and distribution systems.\n\nIt does not evaluate specific CI/CD platforms, specific registry implementations, or specific build tool configurations.",
  "position_statement": "Any system that executes external code inherits its authority unless it can independently verify that authority at execution time. No widely deployed execution pipeline in the current software ecosystem performs this verification.\n\nThe structural condition is a mismatch between control and verification. Execution pipelines determine what code runs in production environments, what credentials are accessible during build and deployment, and what artifacts are published to distribution channels. These are control plane functions. They are exercised without control plane governance.\n\nDistribution is treated as trust. A package published to a registry is treated as authorized to execute. A GitHub Action referenced by tag is treated as authorized to access pipeline secrets. A CI/CD dependency is treated as authorized to inherit the build environment's credentials. In each case, the authorization decision is not made. It is assumed from the act of distribution.\n\nThe system cannot distinguish between receiving a package and granting it control.",
  "context": "Together with CHQ-P-2026-014 (Management Plane Deterministic Control), this Position establishes that control plane authority exists in two locations the traditional security model does not govern: management infrastructure and execution pipelines. P-014 describes control plane authority in systems designed to manage. P-015 describes control plane authority in systems designed to build and distribute. Both exercise authority without verification at the point of execution.\n\nCHQ-P-2026-013 (Portable Developer Identity): Developer identity portability is the propagation mechanism that execution authority inheritance exploits. P-013 establishes that portable identity means portable compromise. P-015 establishes the structural reason: portable identity carries portable execution authority, and no system verifies that authority at the point of use.\n\nCHQ-P-2026-011 (Tool Presence ≠ Functioning Control): Trivy was deployed as a security scanner. Its presence in CI/CD pipelines was evidence of security practice. Its compromise converted that presence into an attack vector. P-011's claim is directly instantiated.\n\nCHQ-P-2026-002 (Verification Collapse): P-015 identifies a specific domain where verification collapse is structural. Execution pipelines are the domain in which the verification primitive that would prevent inherited authority exploitation does not exist at scale.",
  "governance_condition": "Execution pipelines exercise three control plane functions without control plane governance:\n\nCode selection. Pipelines determine which code executes in the build and deployment environment. The selection is based on references (tags, version numbers, package names) that can be mutated without detection.\n\nCredential exposure. Pipelines expose credentials to executing code as a design feature. Build secrets, publish tokens, cloud credentials, and API keys are available to any code that executes in the pipeline context. The credential boundary is the execution boundary. There is no intermediate verification layer.\n\nDistribution authority. Pipelines publish artifacts to registries, container repositories, and package managers. Publication authority is inherited from pipeline credentials, not independently granted. A compromised pipeline publishes with the same authority as a legitimate one.\n\nA-031 (Credential compromise within a registry produces damage bounded by that registry's scope) is retired on issuance. A single credential theft in one registry produced authenticated actions across four additional registries within days. Registry scope is not a containment boundary. It is a propagation surface.\n\nA-033 (Software distribution channels are passive delivery mechanisms that do not exercise execution authority) is under pressure on issuance. Registries, package managers, and CI/CD pipelines are governed as delivery infrastructure. P-015 establishes they function as control planes. They determine what code executes, what credentials are exposed, and what artifacts are published.\n\nA-032 (Management plane authority bounded by identity enforcement) is under additional pressure. Execution pipelines exercise management-plane-equivalent authority without passing through identity enforcement.\n\nA-021 (Security authority persists through delegation chains) is under additional pressure. Execution pipelines delegate authority through dependency resolution, action references, and build tool invocation. None of these delegation points verify that the delegated authority is still valid or that the delegatee is the expected entity.\n\nA-020 (Control plane integrity can be verified independently of data plane activity) is under additional pressure. Execution pipelines are a control plane whose integrity cannot be verified from outside the pipeline.",
  "implications": [
    "Systems responsible for authorization can execute inherited authority from compromised execution pipelines, even where internal control design is otherwise sound. Authorization systems are built and deployed through the same execution pipelines as every other software component.",
    "The security model for software distribution assumes that provenance implies authorization. It does not. Provenance establishes origin. Authorization requires independent verification of the right to execute with specific privileges in a specific context."
  ],
  "implications_text": "The structural consequence is universal across the software ecosystem. It is not specific to any language, registry, CI/CD platform, or deployment target. It is a property of how execution authority is granted: implicitly, through distribution, without verification.\n\nSystems responsible for authorization can execute inherited authority from compromised execution pipelines, even where internal control design is otherwise sound. Authorization systems are built and deployed through the same execution pipelines as every other software component. They inherit the same unverified authority.\n\nThe position's force reduces in environments where every execution step independently verifies the authority of the code it runs: reproducible builds from source with cryptographic attestation, hardware-rooted signing of every artifact at every stage, runtime verification of provenance before credential exposure. These environments exist in theory. None are widely deployed at ecosystem scale.",
  "exclusions": [
    "Prescriptive pipeline hardening guidance",
    "Specific dependency pinning recommendations",
    "Vendor-specific CI/CD security configurations",
    "Regulatory compliance requirements for software supply chain governance"
  ],
  "supersedes": null,
  "amendments": "AMD-001; AMD-2026-09-22-POSITION-RECORD-CORRECTIVE-WAVE; CHQ-RAT-2026-001-CANONICAL-TEXT-EXECUTION-WAVE; AMD-002",
  "amendment_note": "AMENDMENT AMD-001 · JULY 24, 2026 · REINFORCEMENT\nWindow reinforcement recorded. The July 2026 npm publishing campaign executed through legitimate release pipelines whose OIDC identities carried publishing authority with no primitive validating that the authority was correctly held. Provenance verified continuity throughout; the pipelines executed compromised authority. Canonical evidence basis and counts are unchanged; the reinforcement is recorded at the evidence layer.\n\nAMENDMENT AMD-2026-09-22-POSITION-RECORD-CORRECTIVE-WAVE · SEPTEMBER 22, 2026 · POSITION RECORD STANDARD CORRECTION. Canonical field semantics, evidence counts, identifiers, independence wording, and publication integrity corrected in one dated wave.\n\nAMENDMENT CHQ-RAT-2026-001-CANONICAL-TEXT-EXECUTION-WAVE · SEPTEMBER 22, 2026 · CANONICAL TEXT EXECUTION. Scheduled prose constructions rewritten for grammatical clarity without changing the underlying judgment.\n\nAMENDMENT AMD-002 · SEPTEMBER 22, 2026 · REINFORCEMENT\nWindow reinforcement recorded. In the operator-environment incident of 19 July 2026 (CHQ-EX-2026-025), agents used a path-traversal flaw in the artifact repository tier (CVE-2026-66384, entered in the federal exploited catalog on 27 August 2026) for egress and lateral movement. The artifact repository is an execution pipeline component whose authority was exercised by an actor it had no primitive to validate. The canonical evidence basis and counts are unchanged; the reinforcement is recorded at the evidence layer (CHQ-ED-2026-030). Related: CHQ-P-2026-017.",
  "reference_conditions": [
    "Authored independently of any subscribing organization",
    "Not tailored to a specific contractual, commercial, or advocacy interest",
    "Subsequent analysis based only on new evidence"
  ],
  "evidential_record": {
    "title": "CybersecurityHQ Execution Pipeline Authority Evidence",
    "docket": "CHQ-ED-2026-015",
    "exhibits": [
      "CHQ-EX-2026-009",
      "CHQ-EX-2026-010",
      "CHQ-EX-2026-012",
      "CHQ-EX-2026-013"
    ],
    "signals": [
      "SN-2026-03-19-01",
      "SN-2026-03-20-01",
      "SN-2026-03-23-01",
      "SN-2026-03-24-02",
      "SN-2026-03-25-01",
      "SN-2026-03-17-02"
    ]
  },
  "related_positions": [
    "CHQ-P-2026-002",
    "CHQ-P-2026-011",
    "CHQ-P-2026-013",
    "CHQ-P-2026-014",
    "CHQ-P-2026-016",
    "CHQ-P-2026-017"
  ],
  "pdf_hash": "fc8f45b5472c2f344883edc2bfeeed6ecfa5864d56bf4b7593f712083c1af8dd",
  "prior_hashes": [
    {
      "version": "v1.3",
      "sha256": "ecc20d8edd976934b87354743c25a2949c7c21e1ea34848b8517d89f4f9e3a56"
    }
  ],
  "authority_derivation_text": "No constraint derivation applies. This is a standalone Position.",
  "canonical_hash": "fc8f45b5472c2f344883edc2bfeeed6ecfa5864d56bf4b7593f712083c1af8dd"
}
```
