Skip to content

GitHub Actions Workflow compromised - no damage done #57

@joeyparrish

Description

@joeyparrish

A vulnerable workflow exposed this repo to risk of manipulation. All GitHub Actions have been disabled pending investigation of this vulnerability.

Existing releases, tags, and branches are clean and have not been poisoned. MD5 sums in release notes can be used to check your binaries. Binaries released via shaka-streamer-binaries on PyPi are also clean.

Metadata

Metadata

Assignees

Labels

priority: P1Big impact or workaround impractical; resolve before feature releasestatus: archivedArchived and locked; will not be updatedtype: CIAn issue with our continuous integration teststype: vulnerabilityA security issue with the project, the CI, or the repo

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions