Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Hotfix for upstream security vulnerability #359

Merged
merged 1 commit into from
Dec 26, 2024
Merged

Conversation

dancfox
Copy link
Contributor

@dancfox dancfox commented Dec 26, 2024

Issue #, if available: https://t.corp.amazon.com/P161046728

Description of changes:

Responding to sev2 escalation. Implementing SecOps guidance to address Potential for Supply Chain Tampering through Upstream Resource Tampering. The root cause is a vulnerability in the upstream repository tj-actions. Mitigating the risk by using the reusable action via a SHA reference so that the action consumed is immutable.

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

…s Potential for Supply Chain Tampering through Upstream Resource Tampering. The root cause is a vulnerability in the upstream repository tj-actions. Mitigating the risk by using the reusable action via a SHA reference so that the action consumed is immutable.
@dancfox dancfox self-assigned this Dec 26, 2024
@dancfox dancfox merged commit 71a4582 into main Dec 26, 2024
1 check passed
@dancfox dancfox deleted the hotfix/sev2-escalation branch December 26, 2024 17:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant