Wow, github action suppy chain attack based on a compromised, re-pointed version number.
Check yourself if you're reliant on tj-actions/changed-files.
https://www.infoworld.com/article/3849245/github-suffers-a-cascading-supply-chain-attack-compromising-ci-cd-secrets.html
#security #github
CISA confirms cascading attack from reviewdog to tj-actions…
Sign in to follow profiles or hashtags, favourite, share and reply to posts. You can also interact from your account on a different server.