Comment on Popular GitHub Action tj-actions/changed-files is compromisedComments−netvarun1y@dang: The original URL (from Step Security, the company that discovered this flaw) is a better source for this:https://www.stepsecurity.io/blog/harden-runner-detection-tj-...−moyerOP1yYeah maybe we can merge with https://news.ycombinator.com/item?id=43367987−dang1yComments moved thither. Thanks!
Comments
@dang: The original URL (from Step Security, the company that discovered this flaw) is a better source for this:
https://www.stepsecurity.io/blog/harden-runner-detection-tj-...
Yeah maybe we can merge with https://news.ycombinator.com/item?id=43367987
Comments moved thither. Thanks!