Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Review/Replace use of third party gh actions #7853

Open
aruniverse opened this issue Mar 17, 2025 · 0 comments
Open

Review/Replace use of third party gh actions #7853

aruniverse opened this issue Mar 17, 2025 · 0 comments

Comments

@aruniverse
Copy link
Member

Thank you @shubham-stepsecurity for reporting this! We have deleted said logs, reviewed usage, and working on following up with this.

Originally posted by @aruniverse in #7852

CVE-2025-30066 has been resolved, and the malicious code within the action has been removed. Nevertheless we should review and replace our dependency on these third party action for our simple usage.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant