Application Security Compromised SpotBugs Token Led to GitHub Actions Supply Chain Hack Evidence shows a SpotBugs token compromised in December 2024 was used in the March 2025 GitHub Actions supply chain attack. Ionut ArghireApril 4, 2025
Supply Chain Security Impact, Root Cause of GitHub Actions Supply Chain Hack Revealed More details have come to light on the recent supply chain attack targeting GitHub Actions, including its root cause. Eduard KovacsMarch 21, 2025
Application Security Popular GitHub Action Targeted in Supply Chain Attack The tj-actions/changed-files GitHub Action, which is used in 23,000 repositories, has been targeted in a supply chain attack. Eduard KovacsMarch 17, 2025