-
Notifications
You must be signed in to change notification settings - Fork 13
Closed
Labels
priority: P1Big impact or workaround impractical; resolve before feature releaseBig impact or workaround impractical; resolve before feature releasestatus: archivedArchived and locked; will not be updatedArchived and locked; will not be updatedtype: CIAn issue with our continuous integration testsAn issue with our continuous integration teststype: vulnerabilityA security issue with the project, the CI, or the repoA security issue with the project, the CI, or the repo
Milestone
Description
A vulnerable workflow exposed this repo to risk of manipulation. All GitHub Actions have been disabled pending investigation of this vulnerability.
Existing releases, tags, and branches are clean and have not been poisoned. MD5 sums in release notes can be used to check your binaries. Binaries released via shaka-streamer-binaries on PyPi are also clean.
Metadata
Metadata
Assignees
Labels
priority: P1Big impact or workaround impractical; resolve before feature releaseBig impact or workaround impractical; resolve before feature releasestatus: archivedArchived and locked; will not be updatedArchived and locked; will not be updatedtype: CIAn issue with our continuous integration testsAn issue with our continuous integration teststype: vulnerabilityA security issue with the project, the CI, or the repoA security issue with the project, the CI, or the repo