menu
techminis

A naukri.com initiative

google-web-stories
source image

Kaspersky

2w

read

333

img
dot

Image Credit: Kaspersky

Supply chain attack via GitHub Action | Kaspersky official blog

  • Attackers compromised the popular GitHub Action tj-actions/changed-files, used in over 23,000 repositories, leading to a security vulnerability.
  • GitHub Actions are workflow patterns that automate common DevOps tasks triggering when specific events occur on GitHub.
  • The tj-actions/changed-files GitHub Action was infected with malicious code, disguised as the updateFeatures function.
  • Lessons from the incident include the need for information-security hygiene throughout the entire software development lifecycle and proper secrets management in GitHub Actions.

Read Full Article

like

20 Likes

For uninterrupted reading, download the app