You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Fix supply chain security vulnerability in TruffleHog installation
- Replace unpinned install script with direct binary download from GitHub releases
- Eliminates risk of mutable main branch script being compromised
- Downloads specific versioned binary directly from trusted GitHub releases
- More secure and deterministic installation process
- Addresses supply chain security best practices
0 commit comments