Skip to content

Comment on Trivy under attack again: Widespread GitHub Actions tag compromise secretsparent

Comments

So, in the context of me questioning "yes, but exactly how is this supposed to work", you're essentially punting the question into a black box that won't betray us.

In the real world, though, we don't have a magic little black box: we have to actually implement that.

The only answer I have seen from real world security teams is variations of "why wouldn't we be keeping up with updates?", and that's an unpinned dep.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.