home.social

#githubactions — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #githubactions, aggregated by home.social.

  1. Oh no, GitHub Actions is #down again! 🚨 Quick, everyone act surprised while desperately refreshing your email for OTPs like it's 1999. 🙄 But don't worry, at least you can scroll through an endless list of country codes while you wait! 🌍💡
    githubstatus.com/?today #GitHubActions #Emergency #Refresh #CountryCodes #TechHumor #HackerNews #ngated

  2. Oh no, GitHub Actions is #down again! 🚨 Quick, everyone act surprised while desperately refreshing your email for OTPs like it's 1999. 🙄 But don't worry, at least you can scroll through an endless list of country codes while you wait! 🌍💡
    githubstatus.com/?today #GitHubActions #Emergency #Refresh #CountryCodes #TechHumor #HackerNews #ngated

  3. Oh no, GitHub Actions is #down again! 🚨 Quick, everyone act surprised while desperately refreshing your email for OTPs like it's 1999. 🙄 But don't worry, at least you can scroll through an endless list of country codes while you wait! 🌍💡
    githubstatus.com/?today #GitHubActions #Emergency #Refresh #CountryCodes #TechHumor #HackerNews #ngated

  4. Oh no, GitHub Actions is #down again! 🚨 Quick, everyone act surprised while desperately refreshing your email for OTPs like it's 1999. 🙄 But don't worry, at least you can scroll through an endless list of country codes while you wait! 🌍💡
    githubstatus.com/?today #GitHubActions #Emergency #Refresh #CountryCodes #TechHumor #HackerNews #ngated

  5. Oh no, GitHub Actions is #down again! 🚨 Quick, everyone act surprised while desperately refreshing your email for OTPs like it's 1999. 🙄 But don't worry, at least you can scroll through an endless list of country codes while you wait! 🌍💡
    githubstatus.com/?today #GitHubActions #Emergency #Refresh #CountryCodes #TechHumor #HackerNews #ngated

  6. I've been running Github Actions with custom runner images on a k8s cluster for about year and a half by now - and I could attest that this is absolute shitshow, especially in a last few releases.

    Like, since December each upgrade ends in a troubleshooting because of the bugs and just missing changes.

    Latest one follow the charge: helm upgrade of controller went ok, the GHA controller got upgraded to the right version; then the runners got upgraded (entities corresponding to the actual pods spawned for jobs); but the listeners (entity responsible for events from Github and represented by listener pod) are still of previous version. Thus action spawns runner pods of previous version.

    WAT?

    Update for clarity: you may upgrade one component, but you have to uninstall and install again another, while both of them are parts of the same release.

    #kubernetes #Microsoft #GithubActions

  7. I've been running Github Actions with custom runner images on a k8s cluster for about year and a half by now - and I could attest that this is absolute shitshow, especially in a last few releases.

    Like, since December each upgrade ends in a troubleshooting because of the bugs and just missing changes.

    Latest one follow the charge: helm upgrade of controller went ok, the GHA controller got upgraded to the right version; then the runners got upgraded (entities corresponding to the actual pods spawned for jobs); but the listeners (entity responsible for events from Github and represented by listener pod) are still of previous version. Thus action spawns runner pods of previous version.

    WAT?

    Update for clarity: you may upgrade one component, but you have to uninstall and install again another, while both of them are parts of the same release.

    #kubernetes #Microsoft #GithubActions

  8. I've been running Github Actions with custom runner images on a k8s cluster for about year and a half by now - and I could attest that this is absolute shitshow, especially in a last few releases.

    Like, since December each upgrade ends in a troubleshooting because of the bugs and just missing changes.

    Latest one follow the charge: helm upgrade of controller went ok, the GHA controller got upgraded to the right version; then the runners got upgraded (entities corresponding to the actual pods spawned for jobs); but the listeners (entity responsible for events from Github and represented by listener pod) are still of previous version. Thus action spawns runner pods of previous version.

    WAT?

    Update for clarity: you may upgrade one component, but you have to uninstall and install again another, while both of them are parts of the same release.

    #kubernetes #Microsoft #GithubActions

  9. I've been running Github Actions with custom runner images on a k8s cluster for about year and a half by now - and I could attest that this is absolute shitshow, especially in a last few releases.

    Like, since December each upgrade ends in a troubleshooting because of the bugs and just missing changes.

    Latest one follow the charge: helm upgrade of controller went ok, the GHA controller got upgraded to the right version; then the runners got upgraded (entities corresponding to the actual pods spawned for jobs); but the listeners (entity responsible for events from Github and represented by listener pod) are still of previous version. Thus action spawns runner pods of previous version.

    WAT?

    Update for clarity: you may upgrade one component, but you have to uninstall and install again another, while both of them are parts of the same release.

    #kubernetes #Microsoft #GithubActions

  10. I've been running Github Actions with custom runner images on a k8s cluster for about year and a half by now - and I could attest that this is absolute shitshow, especially in a last few releases.

    Like, since December each upgrade ends in a troubleshooting because of the bugs and just missing changes.

    Latest one follow the charge: helm upgrade of controller went ok, the GHA controller got upgraded to the right version; then the runners got upgraded (entities corresponding to the actual pods spawned for jobs); but the listeners (entity responsible for events from Github and represented by listener pod) are still of previous version. Thus action spawns runner pods of previous version.

    WAT?

    Update for clarity: you may upgrade one component, but you have to uninstall and install again another, while both of them are parts of the same release.

    #kubernetes #Microsoft #GithubActions

  11. Megalodon: 5.561 repository GitHub compromessi in sei ore con workflow CI/CD malevoli

    In sei ore il 18 maggio 2026, la campagna automatizzata Megalodon ha iniettato 5.718 commit malevoli in 5.561 repository GitHub, esfiltrandone credenziali cloud, chiavi SSH e segreti CI/CD verso un C2 esterno. L'operazione, collegata al gruppo TeamPCP, rappresenta uno degli attacchi alla supply chain dello sviluppo software più rapidi mai documentati e ha spinto npm a invalidare migliaia di token di accesso con bypass 2FA.

    insicurezzadigitale.com/megalo

  12. Megalodon: 5.561 repository GitHub compromessi in sei ore con workflow CI/CD malevoli

    In sei ore il 18 maggio 2026, la campagna automatizzata Megalodon ha iniettato 5.718 commit malevoli in 5.561 repository GitHub, esfiltrandone credenziali cloud, chiavi SSH e segreti CI/CD verso un C2 esterno. L'operazione, collegata al gruppo TeamPCP, rappresenta uno degli attacchi alla supply chain dello sviluppo software più rapidi mai documentati e ha spinto npm a invalidare migliaia di token di accesso con bypass 2FA.

    insicurezzadigitale.com/megalo

  13. Megalodon: 5.561 repository GitHub compromessi in sei ore con workflow CI/CD malevoli

    In sei ore il 18 maggio 2026, la campagna automatizzata Megalodon ha iniettato 5.718 commit malevoli in 5.561 repository GitHub, esfiltrandone credenziali cloud, chiavi SSH e segreti CI/CD verso un C2 esterno. L'operazione, collegata al gruppo TeamPCP, rappresenta uno degli attacchi alla supply chain dello sviluppo software più rapidi mai documentati e ha spinto npm a invalidare migliaia di token di accesso con bypass 2FA.

    insicurezzadigitale.com/megalo

  14. Megalodon: 5.561 repository GitHub compromessi in sei ore con workflow CI/CD malevoli

    In sei ore il 18 maggio 2026, la campagna automatizzata Megalodon ha iniettato 5.718 commit malevoli in 5.561 repository GitHub, esfiltrandone credenziali cloud, chiavi SSH e segreti CI/CD verso un C2 esterno. L'operazione, collegata al gruppo TeamPCP, rappresenta uno degli attacchi alla supply chain dello sviluppo software più rapidi mai documentati e ha spinto npm a invalidare migliaia di token di accesso con bypass 2FA.

    insicurezzadigitale.com/megalo

  15. Megalodon: 5.561 repository GitHub compromessi in sei ore con workflow CI/CD malevoli

    In sei ore il 18 maggio 2026, la campagna automatizzata Megalodon ha iniettato 5.718 commit malevoli in 5.561 repository GitHub, esfiltrandone credenziali cloud, chiavi SSH e segreti CI/CD verso un C2 esterno. L'operazione, collegata al gruppo TeamPCP, rappresenta uno degli attacchi alla supply chain dello sviluppo software più rapidi mai documentati e ha spinto npm a invalidare migliaia di token di accesso con bypass 2FA.

    insicurezzadigitale.com/megalo

  16. 🦈 Megalodon: Mass GitHub Repo Backdooring via CI Workflows

    「 On May 18, 2026, an automated campaign codenamed megalodon pushed 5,718 malicious commits to 5,561 GitHub repositories in a six-hour window 」

    safedep.io/megalodon-mass-gith

    #github #githubactions #cybersecurity #opensource

  17. 🦈 Megalodon: Mass GitHub Repo Backdooring via CI Workflows

    「 On May 18, 2026, an automated campaign codenamed megalodon pushed 5,718 malicious commits to 5,561 GitHub repositories in a six-hour window 」

    safedep.io/megalodon-mass-gith

    #github #githubactions #cybersecurity #opensource

  18. 🦈 Megalodon: Mass GitHub Repo Backdooring via CI Workflows

    「 On May 18, 2026, an automated campaign codenamed megalodon pushed 5,718 malicious commits to 5,561 GitHub repositories in a six-hour window 」

    safedep.io/megalodon-mass-gith

    #github #githubactions #cybersecurity #opensource

  19. 🦈 Megalodon: Mass GitHub Repo Backdooring via CI Workflows

    「 On May 18, 2026, an automated campaign codenamed megalodon pushed 5,718 malicious commits to 5,561 GitHub repositories in a six-hour window 」

    safedep.io/megalodon-mass-gith

    #github #githubactions #cybersecurity #opensource

  20. 🦈 Megalodon: Mass GitHub Repo Backdooring via CI Workflows

    「 On May 18, 2026, an automated campaign codenamed megalodon pushed 5,718 malicious commits to 5,561 GitHub repositories in a six-hour window 」

    safedep.io/megalodon-mass-gith

    #github #githubactions #cybersecurity #opensource

  21. Level up your workflow! 🚀 Learn how to automate builds, deployments, and security checks with GitHub Actions. A quick guide to mastering CI/CD – check it out! 💻 #GitHubActions #CICD #DevOps

    youtube.com/watch?v=FfT7DDdkZfc

  22. Level up your workflow! 🚀 Learn how to automate builds, deployments, and security checks with GitHub Actions. A quick guide to mastering CI/CD – check it out! 💻 #GitHubActions #CICD #DevOps

    youtube.com/watch?v=FfT7DDdkZfc

  23. Level up your workflow! 🚀 Learn how to automate builds, deployments, and security checks with GitHub Actions. A quick guide to mastering CI/CD – check it out! 💻 #GitHubActions #CICD #DevOps

    youtube.com/watch?v=FfT7DDdkZfc

  24. Level up your workflow! 🚀 Learn how to automate builds, deployments, and security checks with GitHub Actions. A quick guide to mastering CI/CD – check it out! 💻 #GitHubActions #CICD #DevOps

    youtube.com/watch?v=FfT7DDdkZfc

  25. GitHub Actions Supply Chain Attack Exfiltrates CI/CD Credentials

    A sneaky supply chain attack on GitHub Actions has led to the theft of CI/CD credentials, with hackers using a clever trick to redirect tags to fake commits that hide malicious code. By masquerading as legitimate commits, attackers were able to execute arbitrary code and evade pull request reviews.

    osintsights.com/github-actions

    #SupplyChainAttack #GithubActions #CicdCredentials #ImposterCommits #EmergingThreats

  26. Shai-Hulud worm infects another npm package

    A copycat of the notorious Shai-Hulud worm has struck again, infecting another npm package by exploiting a GitHub Actions misconfiguration. This latest attack follows a similar pattern that recently prompted TanStack to rethink its approach to accepting outside code contributions.

    osintsights.com/shai-hulud-wor

    #Shaihulud #Npm #GithubActions #SupplyChain #MalwareOperations

  27. Mini Shai-Hulud: TeamPCP compromette 160+ pacchetti npm e PyPI in un supply chain attack che ha colpito TanStack, Mistral AI e OpenAI

    Tra il 11 e il 14 maggio 2026, il gruppo TeamPCP ha compromesso oltre 160 pacchetti npm e 2 PyPI in un supply chain attack di nuova generazione soprannominato 'Mini Shai-Hulud'. Attraverso l'avvelenamento della cache GitHub Actions, il malware si è auto-propagato nei namespace di TanStack, Mistral AI e UiPath. Il pacchetto node-ipc (822K download settimanali) è stato compromesso separatamente con un payload che rubava 90+ categorie di credenziali. Tra le vittime: due dipendenti di OpenAI.

    insicurezzadigitale.com/mini-s

  28. Mini Shai-Hulud: TeamPCP compromette 160+ pacchetti npm e PyPI in un supply chain attack che ha colpito TanStack, Mistral AI e OpenAI

    Tra il 11 e il 14 maggio 2026, il gruppo TeamPCP ha compromesso oltre 160 pacchetti npm e 2 PyPI in un supply chain attack di nuova generazione soprannominato 'Mini Shai-Hulud'. Attraverso l'avvelenamento della cache GitHub Actions, il malware si è auto-propagato nei namespace di TanStack, Mistral AI e UiPath. Il pacchetto node-ipc (822K download settimanali) è stato compromesso separatamente con un payload che rubava 90+ categorie di credenziali. Tra le vittime: due dipendenti di OpenAI.

    insicurezzadigitale.com/mini-s

  29. Mini Shai-Hulud: TeamPCP compromette 160+ pacchetti npm e PyPI in un supply chain attack che ha colpito TanStack, Mistral AI e OpenAI

    Tra il 11 e il 14 maggio 2026, il gruppo TeamPCP ha compromesso oltre 160 pacchetti npm e 2 PyPI in un supply chain attack di nuova generazione soprannominato 'Mini Shai-Hulud'. Attraverso l'avvelenamento della cache GitHub Actions, il malware si è auto-propagato nei namespace di TanStack, Mistral AI e UiPath. Il pacchetto node-ipc (822K download settimanali) è stato compromesso separatamente con un payload che rubava 90+ categorie di credenziali. Tra le vittime: due dipendenti di OpenAI.

    insicurezzadigitale.com/mini-s

  30. Mini Shai-Hulud: TeamPCP compromette 160+ pacchetti npm e PyPI in un supply chain attack che ha colpito TanStack, Mistral AI e OpenAI

    Tra il 11 e il 14 maggio 2026, il gruppo TeamPCP ha compromesso oltre 160 pacchetti npm e 2 PyPI in un supply chain attack di nuova generazione soprannominato 'Mini Shai-Hulud'. Attraverso l'avvelenamento della cache GitHub Actions, il malware si è auto-propagato nei namespace di TanStack, Mistral AI e UiPath. Il pacchetto node-ipc (822K download settimanali) è stato compromesso separatamente con un payload che rubava 90+ categorie di credenziali. Tra le vittime: due dipendenti di OpenAI.

    insicurezzadigitale.com/mini-s

  31. Mini Shai-Hulud: TeamPCP compromette 160+ pacchetti npm e PyPI in un supply chain attack che ha colpito TanStack, Mistral AI e OpenAI

    Tra il 11 e il 14 maggio 2026, il gruppo TeamPCP ha compromesso oltre 160 pacchetti npm e 2 PyPI in un supply chain attack di nuova generazione soprannominato 'Mini Shai-Hulud'. Attraverso l'avvelenamento della cache GitHub Actions, il malware si è auto-propagato nei namespace di TanStack, Mistral AI e UiPath. Il pacchetto node-ipc (822K download settimanali) è stato compromesso separatamente con un payload che rubava 90+ categorie di credenziali. Tra le vittime: due dipendenti di OpenAI.

    insicurezzadigitale.com/mini-s