chaospatterns@lemmy.world to Programming@programming.devEnglish · 3 days agoPopular GitHub Action tj-actions/changed-files is compromised with a payload that appears to attempt to dump secretssemgrep.devexternal-linkmessage-square2fedilinkarrow-up154arrow-down11 cross-posted to: hackernews@lemmy.bestiver.se
arrow-up153arrow-down1external-linkPopular GitHub Action tj-actions/changed-files is compromised with a payload that appears to attempt to dump secretssemgrep.devchaospatterns@lemmy.world to Programming@programming.devEnglish · 3 days agomessage-square2fedilink cross-posted to: hackernews@lemmy.bestiver.se
minus-squarechaospatterns@lemmy.worldOPlinkfedilinkEnglisharrow-up19·3 days agoHere’s a good reason why you should pin to specific sha hashes, not just release versions.
Here’s a good reason why you should pin to specific sha hashes, not just release versions.