Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Pin hash to a previous version in order to avoid the exploit#3374

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Merged
cmaureir merged 1 commit into3.13fromfix_tj_actions
Mar 15, 2025

Conversation

cmaureir
Copy link
Collaborator

This uses another version (v44) where I could find the hash (we currently used v45).

In summary, the repo got compromised and all the tags versions point to a malicius commit that includes a function to expose the secrets on the github action logs, so people can fetch them.

This uses another version (v44) where I could find the hash(we currently used v45).In summary, the repo got compromised and all the tags versionspoint to a malicius commit that includes a function to exposethe secrets on the github action logs, so people can fetch them.
@cmaureircmaureir merged commit01e2ca8 into3.13Mar 15, 2025
4 checks passed
marcorichetta added a commit to marcorichetta/python-docs-es that referenced this pull requestApr 4, 2025
cmaureir pushed a commit that referenced this pull requestApr 4, 2025
Per discussion in issue#3373, this PR update`tj-actions/changed-files` to its latest version[v46](https://github.com/tj-actions/changed-files/releases/tag/v46.0.3).Related PR:#3374Supersedes#3377
Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment
Reviewers

@rtobarrtobarrtobar approved these changes

Assignees
No one assigned
Labels
None yet
Projects
None yet
Milestone
No milestone
Development

Successfully merging this pull request may close these issues.

2 participants
@cmaureir@rtobar

[8]ページ先頭

©2009-2025 Movatter.jp