#reviewdog — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #reviewdog, aggregated by home.social.
-
I wrote a script to show the exact versions of Actions used in your workflows on GitHub Actions.
It uses the audit logs (or just a list of workflow runs, for a single repo), grabs the workflow logs, and shows which commit was downloaded for each Action.
It’s useful in cases like the tj-actions/changed-files and reviewdog compromises.
https://github.com/github/audit-actions-workflow-runs
#DevSecOps #SupplyChainSecurity #Actions #CiCd #GitHub #TJActions #ReviewDog
-
⚠️ Another GitHub Action was hacked ☣️, reviewdog/action-setup v1, again leaking secrets in workflow logs
Wiz is reporting that it was used in the hack of tj-actions/changed-files, and that other Actions under reviewdog were also affected
https://www.wiz.io/blog/new-github-action-supply-chain-attack-reviewdog-action-setup
It was discovered by Adnan Khan and posted on X
Malicious commit: https://github.com/reviewdog/action-setup/commit/f0d342
Hash: f0d342d24037bb11d26b9bd8496e0808ba32e9ec