{
  "canonicalUrl": "https://xn--mwe.com/supply-chain-assurance/incident-playbooks/scip-k08-001/",
  "contain": [
    "block new artifacts from affected key",
    "freeze promotion",
    "preserve installed-state evidence"
  ],
  "detect": [
    "revocation or supplier notice",
    "signature anomaly",
    "unexpected key fingerprint"
  ],
  "evidence": [
    "notice",
    "key history",
    "affected artifact inventory",
    "decision and retest results"
  ],
  "id": "SCIP-K08-001",
  "recover": [
    "obtain independently verified successor key",
    "revalidate artifacts from trusted source",
    "rotate trust stores"
  ],
  "releaseId": "K12-2026-08-16",
  "scenario": "compromised supplier signing key"
}
