3 ms·
That's true. This specific attack was mitigated by hash pinning, but some actions like https://github.com/1Password/load-secrets-action https://github.com/1Pas
by AdrienPoupa 7mo ago
That's true. This specific attack was mitigated by hash pinning, but some actions like https://github.com/1Password/load-secrets-action https://github.com/1Password/load-secrets-action default to using the latest version of an underlying dependency.
- cpuguy83 6mo agoThis attack was not mitigated by hash pinning. The setup-trivy action installs the latest version of trivy unless you specify a version.
- AdrienPoupa 6mo agoOh, I was referring to `aquasecurity/trivy-action` that was changed with a malicious entrypoint for affected tags. Pinned commits were not affected.