the Glasgow Interface Explorer GitHub organization was affected by GHSA-mrrh-fwg8-r2c3, a crude credentials stealer in one of the github actions used as a dependency that also happened to print them unencrypted in the public build logs

ironically, i've used that github action to prevent someone from tampering with the firmware as a part of a system ensuring that the checked-in blob is reproducibly built

0

If you have a fediverse account, you can quote this note from your own instance. Search https://mastodon.social/users/whitequark/statuses/114370303246562927 on your instance and quote it. (Note that quoting is not supported in Mastodon.)