Comment by latexr
6 months ago
> attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline.
I don’t even trust GitHub’s own actions. I used to use only the one to checkout a repository, limited to a specific tag, but then realised that even a tagged version, if it has dependencies which are not themselves tagged, could be compromised, so I stopped and now do the checkout myself. It’s not even that many lines of code, the fact GitHub has a huge npm package with dependencies to do something this basic is insane.
No comments yet
Contribute on Hacker News ↗