@chaospatterns@lemmy.world to Programming@programming.devEnglish • 2 months agoPopular GitHub Action tj-actions/changed-files is compromised with a payload that appears to attempt to dump secretssemgrep.devexternal-linkmessage-square3fedilinkarrow-up159arrow-down11
arrow-up158arrow-down1external-linkPopular GitHub Action tj-actions/changed-files is compromised with a payload that appears to attempt to dump secretssemgrep.dev@chaospatterns@lemmy.world to Programming@programming.devEnglish • 2 months agomessage-square3fedilink
minus-square@chaospatterns@lemmy.worldOPlinkfedilinkEnglish21•2 months agoHere’s a good reason why you should pin to specific sha hashes, not just release versions.