Reader

Compromised GitHub Action Highlights Risks in CI/CD Supply Chains

| InfoQ | Default

The popular tj-actions/changed-files GitHub Action used by thousands of repositories recently compromised those repositories, exposing a critical weakness in how open-source Actions are published and consumed.

By Matt Foster