Source |
The Hacker News |
Identifiant |
6245020 |
Date de publication |
2022-08-10 23:07:07 (vue: 2022-08-11 07:05:32) |
Titre |
GitHub Dependabot Now Alerts Developers On Vulnerable GitHub Actions |
Texte |
Cloud-based code hosting platform GitHub has announced that it will now start sending Dependabot alerts for vulnerable GitHub Actions to help developers fix security issues in CI/CD workflows.
"When a security vulnerability is reported in an action, our team of security researchers will create an advisory to document the vulnerability, which will trigger an alert to impacted repositories," |
Notes |
|
Envoyé |
Oui |
Condensat |
action actions advisory alert alerts announced based ci/cd cloud code create dependabot developers document fix github has help hosting impacted issues now platform reported repositories researchers security sending start team trigger vulnerability vulnerable when which will workflows |
Tags |
Vulnerability
|
Stories |
|
Move |
|