Skip to content

Disabled build-test workflow #2208

Open
@richardlau

Description

@richardlau

FYI @nodejs/docker Out of caution, I've disabled the build-test workflow.

Late Friday night/early Saturday morning, we were informed that this repository had been identified as using actions that had been compromised: https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised:

uses: tj-actions/changed-files@v45

AFAICT the last time the workflow ran was before the action was compromised, so we've been lucky not to leak any secrets.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions