Skip to content

Security: Compromise of reviewdog/action-setup@v1 #54

@joschi

Description

@joschi

https://www.wiz.io/blog/new-github-action-supply-chain-attack-reviewdog-action-setup

Wiz Research has discovered an additional supply chain attack on reviewdog/action-setup@v1, that may have contributed to the compromise of tj-actions/changed-files. At this point we believe this is a chain of supply chain attacks eventually leading to a specific high-value target.

You are certainly aware of this article and the issue.

Is there any way to track the incident? I haven't seen anything in the Security tab in this repository.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions