Skip to content

Comment on How the Trivy supply chain attack harvested credentials from secrets managersparent

Comments

Um ok, but the "setting the name to any string" is not the real problem, which is that an attacker had the ability to write to the repository at all, regardless of the name they choose, no?

As I mentioned below, another mitigation for this kind of supply chain attack is to fork the action repos into your own organization to allow tighter control over their content.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.