Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2025-30154] New GitHub Action supply chain attack: reviewdog/action-setup

Summary

Wiz Research details a second supply chain attack on reviewdog/action-setup (CVE-2025-30154) that may have enabled the tj-actions/changed-files compromise, with links to Coinbase-targeting activity.
Published
Collected

original ↗

Related coverage

back