You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Pin hash to a previous version in order to avoid the exploit
This uses another version (v44) where I could find the hash
(we currently used v45).
In summary, the repo got compromised and all the tags versions
point to a malicius commit that includes a function to expose
the secrets on the github action logs, so people can fetch them.
0 commit comments