The fallout from the malicious tj-actions/changed-files is still being investigated. It is fortuitous that this malicious commit was identified fairly quickly, as further compromise of major OSS

The fallout from the malicious tj-actions/changed-files is still being investigated. It is fortuitous that this malicious commit was identified fairly quickly, as further compromise of major OSS components and projects could lead to a kind of chain reaction.

#infosec #cybersecurity

4 points · 2 comments · view on lemmy.world

2 Comments

jerry@infosec.exchange · 2 pts · 1y (1 reply)

@harrysintonen@infosec.exchange the second and third order impacts of this could get interesting

harrysintonen@infosec.exchange · 2 pts · 1y

@jerry It largely depends on how well the initial impact is cleaned up. I'm hoping we won't see a ton of backdoors in various components next.