March 19 compromise of Aqua Security’s Trivy via GitHub Actions
Article includes list of hashes by Socket.dev
March 19 compromise of Aqua Security’s Trivy via GitHub Actions
Article includes list of hashes by Socket.dev
Direct link to the GitHub discussion (not Security Advisory) about this.
We rotated secrets and tokens, but the process wasn’t atomic and attackers may have been privy to refreshed tokens. We are now taking a more restrictive approach and locking down all automated actions and any token in order to thoroughly eliminate the problem.
I’m having trouble seeing what they changed though.
Andre, do you mean to tell me you still haven’t contained this incident?