[security] Misconfiguration led to CI github token leakage in released artifacts #951
prabhu
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
A potential security vulnerability was reported against the CI workflow used by cdxgen this week. The vulnerability would have given write access to the repo to anyone for up to 10 minutes (duration of a specific workflow) during a release event. Below are some details based on our investigation and the actions being taken:
Details:
Actions taken so far:
Remove sae builds #946
Remove caxa #947
https://github.com/CycloneDX/cdxgen/releases/tag/v10.2.6
Recommendation for users:
Beta Was this translation helpful? Give feedback.
All reactions