-
Notifications
You must be signed in to change notification settings - Fork 57
Open
Description
Title
Compromised aquasecurity/trivy-action detected in GitHub Actions workflows
Body
Compromised aquasecurity/trivy-action detected in GitHub Actions workflows
Our automated platform at StepSecurity has detected that this repository used a compromised version of aquasecurity/trivy-action in its GitHub Actions workflows during the recent Trivy incident.
What happened?
The aquasecurity/trivy-action GitHub Action was compromised, and a malicious version (v0.69.4) was published. Workflow runs in this repository executed a compromised SHA of this action, which may have exposed sensitive information such as secrets, environment variables, or build artifacts.
Compromised SHA detected
aquasecurity/trivy-action@e0198fd2b6e1679e36d32933941182d9afa82f6f
Affected workflow runs
| # | Workflow Run | Workflow File |
|---|---|---|
| 1 | 23308899842 | Workflow |
| 2 | 23308941433 | Workflow |
| 3 | 23310248087 | Workflow |
| 4 | 23310331037 | Workflow |
| 5 | 23311593675 | Workflow |
| 6 | 23313491734 | Workflow |
| 7 | 23314110764 | Workflow |
| 8 | 23315900783 | Workflow |
| 9 | 23320236998 | Workflow |
| 10 | 23324114747 | Workflow |
| 11 | 23324193088 | Workflow |
| 12 | 23324398293 | Workflow |
| 13 | 23325118987 | Workflow |
| 14 | 23326100426 | Workflow |
References
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels