chaospatterns@lemmy.world to Programming@programming.devEnglish · 5 days agoPopular GitHub Action tj-actions/changed-files is compromised with a payload that appears to attempt to dump secretssemgrep.devexternal-linkmessage-square2fedilinkarrow-up15arrow-down10
arrow-up15arrow-down1external-linkPopular GitHub Action tj-actions/changed-files is compromised with a payload that appears to attempt to dump secretssemgrep.devchaospatterns@lemmy.world to Programming@programming.devEnglish · 5 days agomessage-square2fedilink
minus-squarechaospatterns@lemmy.worldOPlinkfedilinkEnglisharrow-up1·5 days agoHere’s a good reason why you should pin to specific sha hashes, not just release versions.
Here’s a good reason why you should pin to specific sha hashes, not just release versions.