[CVE-2025-30154] New GitHub Action supply chain attack: reviewdog/action-setup
wiz.io | incident | CVE-2025-30154 | #supply-chain | #github-actions | #ci-cd | #incident | #threat-research | #cve-2025-30154
Summary
Wiz Research details a second supply chain attack on reviewdog/action-setup (CVE-2025-30154) that may have enabled the tj-actions/changed-files compromise, with links to Coinbase-targeting activity.
- Published
- Collected
Skip to content