SailPoint’s disclosure of a GitHub repository breach following a third-party cyberattack highlights a growing concern in identity governance: vendor risk extends to the development supply chain, and IGA vendors themselves are not immune.

The breach involved a third-party compromise that affected SailPoint’s GitHub repositories. While SailPoint has stated that no customer data was directly impacted, the incident raises important questions about how identity governance vendors secure their own development infrastructure — and what that means for organisations relying on them.

From an IGA perspective, the incident underscores the importance of third-party risk management within identity governance frameworks. Organisations invest in IGA platforms to manage access and reduce risk, but the IGA vendor itself becomes part of the trust chain. If a vendor’s development environment is compromised, the integrity of the platform itself could be at stake.

For identity governance programmes, this incident should prompt a review of vendor security requirements. IGA platforms typically hold privileged access to directory services, HR systems, and critical applications. A compromise of the vendor’s infrastructure could potentially expose these integrations. Organisations should ensure their IGA vendor contracts include specific security requirements for development environments, including access controls, monitoring, and incident notification timelines.

The broader lesson is that identity governance is not just about managing internal access — it extends to governing the identity and access practices of vendors who manage identity infrastructure. Third-party risk assessments should specifically evaluate how IGA vendors secure their own development and deployment pipelines.

For IAM practitioners, the SailPoint GitHub incident is a reminder that trust in identity platforms must be continuously validated, not assumed. Vendor risk management should be an integral component of any identity governance strategy.