Comment on Supply chain attack alert: .github/setup.jsComments−thejaybird3moFor me i feel the attack vector isPublic repo > infect by merge > github runner picks up and gets infected > and github action (from a repo) that then runs on runner getw effected
Comments
For me i feel the attack vector is
Public repo > infect by merge > github runner picks up and gets infected > and github action (from a repo) that then runs on runner getw effected