Hacker News new | ask | show | jobs
Suspicious Tag Change in AWS's GitHub Action: What Happened and Why It Matters (stepsecurity.io)
3 points by varunsharma07 302 days ago
1 comments

How an AWS release rollback triggered the same red flags as a supply chain attack and why treating every semantic version tag change as suspicious is key to protecting your CI/CD pipelines