๊ฐ€์ž… ํ›„ ์ดˆ๋Œ€ ๋งํฌ๋ฅผ ๊ณต์œ ํ•˜๋ฉด ๋™์˜์ƒ ์žฌ์ƒ ๋ฐ ์ดˆ๋Œ€ ๋ณด์ƒ์„ ๋ฐ›์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

23pds (ๅฑฑๅ“ฅ)
@im23pds
Dad/@SlowMist_Team Partner&CISO/#Web3# Security Researcher/RedTeam/Pentester/Aiๅฎ‰ๅ…จ็ŒŽไบบ #bitcoin#
๊ฐ€์ž… June 2014
6K ํŒ”๋กœ์ž‰ ์ค‘    15.2K ํŒฌ
๐Ÿ™‚โ€โ†”๏ธ ็Žฐๅœจๆฏๅคฉไธค็œผไธ€็ๅฐฑๆ˜ฏๆ–ฐ็š„CVEใ€ๆ–ฐ็š„ๆ”ปๅ‡ป ๐Ÿ˜ข
Today's two supply chain incidents are likely connected: 1. `actions-cool/issues-helper` was compromised 2. AntV was compromised shortly after I noticed AntV was using `actions-cool/issues-helper@main` in GitHub Actions. Rspack was not affected because we pin Actions to commit ids via renovate's `pinGitHubActionDigests`. Strongly recommend enabling it.
๋” ๋ณด๊ธฐ