chaospatterns@lemmy.world to Programming@programming.devEnglish · 1 day agoPopular GitHub Action tj-actions/changed-files is compromised with a payload that appears to attempt to dump secretssemgrep.devexternal-linkmessage-square2fedilinkarrow-up148arrow-down11 cross-posted to: hackernews
arrow-up147arrow-down1external-linkPopular GitHub Action tj-actions/changed-files is compromised with a payload that appears to attempt to dump secretssemgrep.devchaospatterns@lemmy.world to Programming@programming.devEnglish · 1 day agomessage-square2fedilink cross-posted to: hackernews
minus-squarechaospatterns@lemmy.worldOPlinkfedilinkEnglisharrow-up16·1 day agoHere’s a good reason why you should pin to specific sha hashes, not just release versions.
Here’s a good reason why you should pin to specific sha hashes, not just release versions.