TGViewer
CatOps CatOps @catops · 5.07K subscribers
Post #2647 1.85K
There are two types of folks: those who pin their dependencies to (often) mutable tags and other pointers, and those who already pin to hash sums.

This is true for GitHub Actions as well. For example, most tags in the tj-actions/changed-files repository were repointed to compromised versions by an attacker, potentially affecting 23,000 repositories until GitHub shut down the entire repository.

Manually pinning dependencies can be tedious, so it's better to utilize tools like Renovate. The SpotOnInc/renovate-config preset does exactly that. Note that you can pin it to a hash sum too, just in case ;)

P.S. If you used that GitHub Action, here is a list of possible mitigation steps: antonbabenko/pre-commit-terraform#837.

#security #github #gha
www.stepsecurity.io Harden-Runner detection: tj-actions/changed-files action is compromised - StepSecurity
  • 👍 2
More from @catops
  1. Oct 6, 2026A colleague of mine wrote an article about data migrations. Handling data migrations witho…
  2. Oct 1, 2026​​I traded my personal information for this report, so you don’t have to! DataDog presents…
  3. Sep 29, 2026A Cybersecurity books bundle by O’Reilly on Humble Bundle. The bundle is fresh and is stil…
  4. Sep 28, 2026​​For today’s Donations Monday, I’d like to remind you about a fundraiser for a pickup tru…
  5. Sep 26, 2026Here’s Datadog’s take on the increased load on CI. In this article they explain how their…
  6. Sep 25, 2026A new chapter of the CatOps Digest is here! https://newsletter.catops.dev/p/catops-digest-…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →