Skip to content

Security: Compromise of reviewdog actions #336

@joschi

Description

@joschi

https://www.wiz.io/blog/new-github-action-supply-chain-attack-reviewdog-action-setup

However, this Action is then used as a component of numerous other actions from reviewdog, including:

  • reviewdog/action-shellcheck
  • reviewdog/action-composite-template
  • reviewdog/action-staticcheck
  • reviewdog/action-ast-grep
  • reviewdog/action-typos

Customers who were using other impacted reviewdog/actions could be impacted, regardless of the version of that action.

This repository is using reviewdog/action-shellcheck which might have been compromised in the incident outlined in the aforementioned article.

Code search: https://github.com/search?q=repo%3AanothrNick%2Fgithub-tag-action%20reviewdog&type=code

Result:
Image

Since the last commit in this repository was more than 6 months ago it should be fine, but better safe than sorry. 😅

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions