Zennoxa Research

Reproducible security research from the team behind Zennoxa Shield — measured data on supply-chain, CI/CD and container risk, with the method and raw numbers so you can re-run every study.

Jul 21, 2026 4 min

Do popular projects pin their base images? We checked 25

Popular projects SHA-pin their GitHub Actions two-thirds of the time — but pin their Docker base images to an immutable digest only 7.6% of the time. Same supply-chain idea, a fraction of the adoption. Reproducible data across 25 repos.

supply-chaindockercontainers
Jul 21, 2026 4 min

Do popular container images drop root? We checked 25 projects

Half of the primary Dockerfiles in 25 popular infra and app projects don't set an explicit non-root USER in their final stage. A fair, caveated look at what static analysis can and can't tell you about container privilege.

containersdockerdockerfile
Jul 21, 2026 5 min

State of GitHub Actions Pinning 2026: we checked 30 popular repos

Across 30 popular public repositories, 1 in 3 GitHub Action references still points at a mutable tag instead of a pinned commit — the exact pattern behind the tj-actions/changed-files and reviewdog compromises. Reproducible data.

supply-chaingithub-actionsci-cd
Jul 21, 2026 4 min

Where static analysis is easy vs hard: a walk through 2,740 OWASP tests

The OWASP Benchmark's 2,740 labelled cases show a clear pattern: SAST nails pattern-local bugs (weak crypto at 100% precision) and struggles with anything that needs dataflow (SQL injection at 39% recall). Here's the whole scorecard — including where our own engine scores zero.

saststatic-analysisowasp
Research — reproducible security studies — Zennoxa Shield