Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Commit01e2ca8

Browse files
authored
Pin hash to a previous version in order to avoid the exploit (#3374)
This uses another version (v44) where I could find the hash (wecurrently used v45).In summary, the repo got compromised and all the tags versions point toa malicius commit that includes a function to expose the secrets on thegithub action logs, so people can fetch them.
1 parent95cd34a commit01e2ca8

File tree

2 files changed

+2
-2
lines changed

2 files changed

+2
-2
lines changed

‎.github/workflows/main.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -52,7 +52,7 @@ jobs:
5252
-name:Obtiene la lista de archivos .po con cambios (sólo en PRs)
5353
if:github.event_name == 'pull_request'
5454
id:changed-po-files
55-
uses:tj-actions/changed-files@v45
55+
uses:tj-actions/changed-files@9200e69727eb73eb060652b19946b8a2fdfb654b
5656
with:
5757
files:|
5858
**/*.po

‎.github/workflows/pr-comment.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@ jobs:
3737
python -m pip install -r base-branch/requirements-own.txt
3838
-name:Obtiene lista de archivos con cambios
3939
id:changed-files
40-
uses:tj-actions/changed-files@v45
40+
uses:tj-actions/changed-files@9200e69727eb73eb060652b19946b8a2fdfb654b
4141
with:
4242
files:|
4343
**/*.po

0 commit comments

Comments
 (0)

[8]ページ先頭

©2009-2025 Movatter.jp