Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

3 points•justsomehuman•6 days ago•1 comment•

1 comment

justsomehuman6 days ago
So these two compromised GitHub Actions, actions-cool/issues-helper and actions-cool/maintain-one-comment with malicious tags in tact have been inexplicably reenabled within the past week. Exposing dependant repos to Mini Shai-Hulud.

Read the full thread on Hacker News →

Related stories