mastodon.green is one of the many independent Mastodon servers you can use to participate in the fediverse.
Plant trees while you use Mastodon. A server originally for people in the EU, but now open for anyone in the world

Administered by:

Server stats:

1.2K
active users

#githubactions

0 posts0 participants0 posts today
Marco Siccardi<p>Just got both Apple Distribution &amp; Installer certs working in GitHub Actions CI for macOS. The only reliable way? Combine them into one .p12.</p> <p>Full write-up: <a href="https://msicc.net/ci-ready-macos-signing-combining-certs-for-github-actions/" rel="nofollow noopener noreferrer" target="_blank">msicc.net/ci-ready-…</a></p> <p>#AppleDev #macOS #CI #GitHubActions #Notarization 👩‍💻 👨‍💻 💻</p>
Python Rennes<p><a href="https://social.breizhcamp.org/tags/CI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CI</span></a> <a href="https://social.breizhcamp.org/tags/github" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>github</span></a> il est désormais possible d'utiliser des versions "free-threaded" de <a href="https://social.breizhcamp.org/tags/Python" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Python</span></a> (sans le global interpreter lock, qui bride la façon de faire de l'exécution concurrente) dans les <a href="https://social.breizhcamp.org/tags/githubactions" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>githubactions</span></a></p><p><a href="https://hugovk.dev/blog/2025/free-threaded-python-on-github-actions/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">hugovk.dev/blog/2025/free-thre</span><span class="invisible">aded-python-on-github-actions/</span></a></p>
Python Rennes<p>Nous avons tous nos bonnes pratiques lorsqu'il s'agit de créer un nouveau <a href="https://social.breizhcamp.org/tags/projet" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>projet</span></a> <a href="https://social.breizhcamp.org/tags/Python" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Python</span></a>, avec l'utilisation de patterns et d'outils éprouvés : lint avec <a href="https://social.breizhcamp.org/tags/ruff" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ruff</span></a> et <a href="https://social.breizhcamp.org/tags/mypy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>mypy</span></a>, hooks avec <a href="https://social.breizhcamp.org/tags/precommit" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>precommit</span></a>, tests avec <a href="https://social.breizhcamp.org/tags/pytest" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>pytest</span></a>, intégration continue <a href="https://social.breizhcamp.org/tags/githubactions" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>githubactions</span></a> : <a href="https://github.com/neubig/starter-repo" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">github.com/neubig/starter-repo</span><span class="invisible"></span></a> </p><p>Libre à chaque personne de faire évoluer le porojet selon ses propres goûts et contraintes.</p>
Hugo van Kemenade<p>GitHub Actions now supports free-threaded Python!</p><p>I wrote up how to add it your workflows so you can start testing free-threaded Python 3.13 and 3.14 with either actions/setup-python or actions/setup-uv.</p><p><a href="https://hugovk.dev/blog/2025/free-threaded-python-on-github-actions/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">hugovk.dev/blog/2025/free-thre</span><span class="invisible">aded-python-on-github-actions/</span></a></p><p><a href="https://mastodon.social/tags/Python" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Python</span></a> <a href="https://mastodon.social/tags/FreeThreaded" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FreeThreaded</span></a> <a href="https://mastodon.social/tags/GitHub" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GitHub</span></a> <a href="https://mastodon.social/tags/GitHubActions" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GitHubActions</span></a> <a href="https://mastodon.social/tags/CI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CI</span></a> <a href="https://mastodon.social/tags/testing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>testing</span></a></p>
Gisela Torres :verified_paw:<p>return(GiS); | Revisa qué módulos de Node.js no estás usando con depcheck y Github Actions | <a href="https://returngis.net/2025/03/revisa-que-modulos-de-node-js-no-estas-usando-con-depcheck-y-github-actions/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">returngis.net/2025/03/revisa-q</span><span class="invisible">ue-modulos-de-node-js-no-estas-usando-con-depcheck-y-github-actions/</span></a> <a href="https://hachyderm.io/tags/Nodejs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Nodejs</span></a> <a href="https://hachyderm.io/tags/DevOps" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DevOps</span></a> <a href="https://hachyderm.io/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DevSecOps</span></a> <a href="https://hachyderm.io/tags/GitHubActions" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GitHubActions</span></a></p>
Lup Yuen Lee 李立源<p>"If you thought <a href="https://qoto.org/tags/GitHubActions" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GitHubActions</span></a> was bad, try mixing in <a href="https://qoto.org/tags/Docker" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Docker</span></a>"</p><p><a href="https://www.feldera.com/blog/the-pain-that-is-github-actions" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">feldera.com/blog/the-pain-that</span><span class="invisible">-is-github-actions</span></a></p>
The New Oil<p><a href="https://mastodon.thenewoil.org/tags/Coinbase" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Coinbase</span></a> was primary target of recent <a href="https://mastodon.thenewoil.org/tags/GitHubActions" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GitHubActions</span></a> breaches</p><p><a href="https://www.bleepingcomputer.com/news/security/coinbase-was-primary-target-of-recent-github-actions-breaches/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/coinbase-was-primary-target-of-recent-github-actions-breaches/</span></a></p><p><a href="https://mastodon.thenewoil.org/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://mastodon.thenewoil.org/tags/GitHub" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GitHub</span></a> <a href="https://mastodon.thenewoil.org/tags/crypto" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>crypto</span></a></p>
LavX News<p>Coinbase Targeted in GitHub Actions Supply Chain Attack: A Deep Dive</p><p>A sophisticated supply chain attack has put Coinbase in the crosshairs, exploiting GitHub Actions to compromise secrets across hundreds of repositories. This article unpacks the technical details of t...</p><p><a href="https://news.lavx.hu/article/coinbase-targeted-in-github-actions-supply-chain-attack-a-deep-dive" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">news.lavx.hu/article/coinbase-</span><span class="invisible">targeted-in-github-actions-supply-chain-attack-a-deep-dive</span></a></p><p><a href="https://mastodon.cloud/tags/news" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>news</span></a> <a href="https://mastodon.cloud/tags/tech" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tech</span></a> <a href="https://mastodon.cloud/tags/GitHubActions" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GitHubActions</span></a> <a href="https://mastodon.cloud/tags/SupplyChainSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SupplyChainSecurity</span></a> <a href="https://mastodon.cloud/tags/Coinbase" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Coinbase</span></a></p>
Christoffer S.<p>(horizon3.ai) What to know about recent Github Actions and Apache Tomcat vulnerabilities—before you investigate <a href="https://www.horizon3.ai/attack-research/attack-blogs/critical-or-clickbait-github-actions-and-apache-tomcat-rce-vulnerabilities-2025/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">horizon3.ai/attack-research/at</span><span class="invisible">tack-blogs/critical-or-clickbait-github-actions-and-apache-tomcat-rce-vulnerabilities-2025/</span></a></p><p>The article from Horizon3 analyzes two recent high-profile vulnerabilities: CVE-2025-30066 affecting GitHub Actions (tj-actions/changed-files) and CVE-2025-24813 affecting Apache Tomcat. Despite widespread publicity, Horizon3.ai's Attack Team found that actual exploitation risk is significantly lower than reported. For the GitHub Actions vulnerability, only one repository among 1,200 examined was exposed, with no evidence of data exfiltration. For Apache Tomcat, analysis of over 10,000 endpoints revealed no vulnerable configurations in production environments. The article emphasizes the importance of prioritizing security responses based on actual risk rather than media hype.</p><p><a href="https://swecyb.com/tags/Cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Cybersecurity</span></a> <a href="https://swecyb.com/tags/GithubActions" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GithubActions</span></a> <a href="https://swecyb.com/tags/Github" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Github</span></a> <a href="https://swecyb.com/tags/Tomcat" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tomcat</span></a> <a href="https://swecyb.com/tags/Apache" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Apache</span></a> <a href="https://swecyb.com/tags/Vulnerability" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Vulnerability</span></a></p>
Winbuzzer<p>GitHub has removed a poisoned Action used in 23,000+ repos after it exfiltrated CI secrets, prompting concerns over supply chain security</p><p><a href="https://mastodon.social/tags/Cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Cybersecurity</span></a> <a href="https://mastodon.social/tags/Microsoft" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Microsoft</span></a> <a href="https://mastodon.social/tags/GitHub" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GitHub</span></a> <a href="https://mastodon.social/tags/CI_CD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CI_CD</span></a> <a href="https://mastodon.social/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DevSecOps</span></a> <a href="https://mastodon.social/tags/CyberThreats" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberThreats</span></a> <a href="https://mastodon.social/tags/GitHubActions" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GitHubActions</span></a> <a href="https://mastodon.social/tags/Malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Malware</span></a> <a href="https://mastodon.social/tags/CodeSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CodeSecurity</span></a> <a href="https://mastodon.social/tags/tjactions" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tjactions</span></a></p><p><a href="https://winbuzzer.com/2025/03/21/github-action-breach-exposes-secrets-in-hundreds-of-repositories-xcxwbn/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">winbuzzer.com/2025/03/21/githu</span><span class="invisible">b-action-breach-exposes-secrets-in-hundreds-of-repositories-xcxwbn/</span></a></p>
LavX News<p>Cascading Supply Chain Attack Exposes Secrets in Over 23,000 GitHub Repositories</p><p>A recent supply chain attack has compromised critical CI/CD secrets across a staggering number of GitHub repositories, revealing vulnerabilities in widely used actions. The breach highlights the inter...</p><p><a href="https://news.lavx.hu/article/cascading-supply-chain-attack-exposes-secrets-in-over-23000-github-repositories" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">news.lavx.hu/article/cascading</span><span class="invisible">-supply-chain-attack-exposes-secrets-in-over-23000-github-repositories</span></a></p><p><a href="https://mastodon.cloud/tags/news" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>news</span></a> <a href="https://mastodon.cloud/tags/tech" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tech</span></a> <a href="https://mastodon.cloud/tags/GitHubActions" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GitHubActions</span></a> <a href="https://mastodon.cloud/tags/SupplyChainSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SupplyChainSecurity</span></a> <a href="https://mastodon.cloud/tags/CISA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CISA</span></a></p>
Lup Yuen Lee 李立源<p>Compromised `reviewdog` <a href="https://qoto.org/tags/GitHubActions" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GitHubActions</span></a> "injected Malicious Code into any CI Workflows using it, dumping the CI Runner memory containing the Workflow Secrets"</p><p><a href="https://www.wiz.io/blog/new-github-action-supply-chain-attack-reviewdog-action-setup" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">wiz.io/blog/new-github-action-</span><span class="invisible">supply-chain-attack-reviewdog-action-setup</span></a></p>
aegilops :github::microsoft:<p>⚠️ Another GitHub Action was hacked ☣️, reviewdog/action-setup v1, again leaking secrets in workflow logs</p><p>Wiz is reporting that it was used in the hack of tj-actions/changed-files, and that other Actions under reviewdog were also affected</p><p><a href="https://www.wiz.io/blog/new-github-action-supply-chain-attack-reviewdog-action-setup" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">wiz.io/blog/new-github-action-</span><span class="invisible">supply-chain-attack-reviewdog-action-setup</span></a></p><p>It was discovered by Adnan Khan and posted on X</p><p>Malicious commit: <a href="https://github.com/reviewdog/action-setup/commit/f0d342" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/reviewdog/action-se</span><span class="invisible">tup/commit/f0d342</span></a></p><p>Hash: f0d342d24037bb11d26b9bd8496e0808ba32e9ec</p><p><a href="https://fosstodon.org/tags/SupplyChain" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SupplyChain</span></a> <a href="https://fosstodon.org/tags/GitHubActions" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GitHubActions</span></a> <a href="https://fosstodon.org/tags/AppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AppSec</span></a> <a href="https://fosstodon.org/tags/Malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Malware</span></a> <a href="https://fosstodon.org/tags/ReviewDog" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ReviewDog</span></a></p>
LavX News<p>Cascading Supply Chain Attack Exposes CI/CD Secrets: A GitHub Action Breach Analysis</p><p>A recent cascading supply chain attack has compromised GitHub Actions, leading to the exposure of CI/CD secrets across thousands of repositories. This incident highlights vulnerabilities in the softwa...</p><p><a href="https://news.lavx.hu/article/cascading-supply-chain-attack-exposes-ci-cd-secrets-a-github-action-breach-analysis" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">news.lavx.hu/article/cascading</span><span class="invisible">-supply-chain-attack-exposes-ci-cd-secrets-a-github-action-breach-analysis</span></a></p><p><a href="https://mastodon.cloud/tags/news" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>news</span></a> <a href="https://mastodon.cloud/tags/tech" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tech</span></a> <a href="https://mastodon.cloud/tags/GitHubActions" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GitHubActions</span></a> <a href="https://mastodon.cloud/tags/SupplyChainSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SupplyChainSecurity</span></a> <a href="https://mastodon.cloud/tags/CICDSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CICDSecurity</span></a></p>
Marco Siccardi :dotnet:<p>I just blogged: Automating Apple Builds: A Practical Guide to GitHub Secrets</p><p><a href="https://msicc.net/automating-apple-builds-a-practical-guide-to-github-secrets/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">msicc.net/automating-apple-bui</span><span class="invisible">lds-a-practical-guide-to-github-secrets/</span></a></p><p><a href="https://dotnet.social/tags/ios" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ios</span></a> <a href="https://dotnet.social/tags/iosdev" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>iosdev</span></a> <a href="https://dotnet.social/tags/githubactions" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>githubactions</span></a> <a href="https://dotnet.social/tags/github" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>github</span></a> <a href="https://dotnet.social/tags/secrets" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>secrets</span></a> <a href="https://dotnet.social/tags/certificates" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>certificates</span></a> <a href="https://dotnet.social/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://dotnet.social/tags/cicd" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cicd</span></a> <a href="https://dotnet.social/tags/automation" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>automation</span></a> <a href="https://dotnet.social/tags/build" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>build</span></a> <a href="https://dotnet.social/tags/deployment" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>deployment</span></a></p>
Marco Siccardi :dotnet:<p>I just blogged: Automating Apple Builds: A Practical Guide to GitHub Secrets</p><p><a href="https://msicc.net/automating-apple-builds-a-practical-guide-to-github-secrets/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">msicc.net/automating-apple-bui</span><span class="invisible">lds-a-practical-guide-to-github-secrets/</span></a></p><p><a href="https://dotnet.social/tags/ios" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ios</span></a> <a href="https://dotnet.social/tags/iosdev" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>iosdev</span></a> <a href="https://dotnet.social/tags/githubactions" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>githubactions</span></a> <a href="https://dotnet.social/tags/github" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>github</span></a> <a href="https://dotnet.social/tags/secrets" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>secrets</span></a> <a href="https://dotnet.social/tags/certificates" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>certificates</span></a> <a href="https://dotnet.social/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://dotnet.social/tags/cicd" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cicd</span></a> <a href="https://dotnet.social/tags/automation" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>automation</span></a> <a href="https://dotnet.social/tags/build" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>build</span></a> <a href="https://dotnet.social/tags/deployment" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>deployment</span></a> <a href="https://msicc.net/automating-apple-builds-a-practical-guide-to-github-secrets/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">msicc.net/automating-apple-bui</span><span class="invisible">lds-a-practical-guide-to-github-secrets/</span></a></p>
LavX News<p>Windows Server 2025 Set to Revolutionize DevOps with New Features in GitHub Actions and Azure DevOps</p><p>The upcoming release of Windows Server 2025, scheduled for general availability on April 1, 2025, promises significant enhancements for developers using GitHub Actions and Azure DevOps. With updated s...</p><p><a href="https://news.lavx.hu/article/windows-server-2025-set-to-revolutionize-devops-with-new-features-in-github-actions-and-azure-devops" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">news.lavx.hu/article/windows-s</span><span class="invisible">erver-2025-set-to-revolutionize-devops-with-new-features-in-github-actions-and-azure-devops</span></a></p><p><a href="https://mastodon.cloud/tags/news" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>news</span></a> <a href="https://mastodon.cloud/tags/tech" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tech</span></a> <a href="https://mastodon.cloud/tags/GitHubActions" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GitHubActions</span></a> <a href="https://mastodon.cloud/tags/WindowsServer2025" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WindowsServer2025</span></a> <a href="https://mastodon.cloud/tags/AzureDevOps" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AzureDevOps</span></a></p>
joschi<p>TIL: pinact is a CLI to edit GitHub Workflow and Composite action files and pin versions of Actions and Reusable Workflows.</p><p><a href="https://github.com/suzuki-shunsuke/pinact" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/suzuki-shunsuke/pin</span><span class="invisible">act</span></a><br><a href="https://hachyderm.io/tags/GitHub" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GitHub</span></a> <a href="https://hachyderm.io/tags/GitHubActions" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GitHubActions</span></a> <a href="https://hachyderm.io/tags/TIL" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TIL</span></a></p>
Beth Pariseau<p>"Another wakeup call:" A <a href="https://hachyderm.io/tags/softwaresupplychain" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>softwaresupplychain</span></a> attack on a widely used GitHub Actions repository renews experts' calls for better <a href="https://hachyderm.io/tags/buildpipeline" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>buildpipeline</span></a> security. <a href="https://hachyderm.io/tags/CICD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CICD</span></a> <a href="https://hachyderm.io/tags/softwaresupplychainsecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>softwaresupplychainsecurity</span></a> <a href="https://hachyderm.io/tags/GitHubActions" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GitHubActions</span></a> <a href="https://www.techtarget.com/searchitoperations/news/366621078/GitHub-Actions-supply-chain-attack-spotlights-CI-CD-risks" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">techtarget.com/searchitoperati</span><span class="invisible">ons/news/366621078/GitHub-Actions-supply-chain-attack-spotlights-CI-CD-risks</span></a></p>
LavX News<p>GitHub Action Supply Chain Attack: A Wake-Up Call for CI/CD Security</p><p>A recent supply chain attack on the popular 'tj-actions/changed-files' GitHub Action has exposed critical CI/CD secrets, affecting over 23,000 repositories. This incident underscores the vulnerabiliti...</p><p><a href="https://news.lavx.hu/article/github-action-supply-chain-attack-a-wake-up-call-for-ci-cd-security" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">news.lavx.hu/article/github-ac</span><span class="invisible">tion-supply-chain-attack-a-wake-up-call-for-ci-cd-security</span></a></p><p><a href="https://mastodon.cloud/tags/news" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>news</span></a> <a href="https://mastodon.cloud/tags/tech" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tech</span></a> <a href="https://mastodon.cloud/tags/GitHubActions" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GitHubActions</span></a> <a href="https://mastodon.cloud/tags/CICDSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CICDSecurity</span></a> <a href="https://mastodon.cloud/tags/SupplyChainAttack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SupplyChainAttack</span></a></p>