Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
#compromised#github#actions#two compromised#github actions#compromised github#reenabled#two compromised github
1 comment
justsomehuman6 days ago
So these two compromised GitHub Actions, actions-cool/issues-helper and actions-cool/maintain-one-comment with malicious tags in tact have been inexplicably reenabled within the past week. Exposing dependant repos to Mini Shai-Hulud.
Read the full thread on Hacker News →
Related stories
- DEV Community · 17 points · 11 days ago
- DEV Community · 10 points · 1 day ago
- Hacker News · 1 points · 4 days ago
- GitHub Actions leaking secrets when Miri output is cachedblog.rust-lang.orgLobsters · 13 points · 8 days ago
- GitHub Actions leaking secrets when Miri output is cachedblog.rust-lang.orgHacker News · 2 points · 9 days ago
- GitHub Actions leaking secrets when Miri output is cachedblog.rust-lang.orgHacker News · 1 points · 8 days ago