Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
undefined | Better HN
0 points
cpuguy83
1mo ago
0 comments
Share
This attack was
not
mitigated by hash pinning. The setup-trivy action installs the latest version of trivy unless you specify a version.
0 comments
default
newest
oldest
AdrienPoupa
1mo ago
Oh, I was referring to `aquasecurity/trivy-action` that was changed with a malicious entrypoint for affected tags. Pinned commits were not affected.
j
/
k
navigate · click thread line to collapse