
Malicious Trivy GitHub Actions releases trigger CI secret rotation
Aqua says attackers used a compromised credential to publish malicious `trivy-action` and `setup-trivy` releases; any affected GitHub Actions pipeline should upgrade and rotate secrets.
NewsSupply ChainCI/CD
2 minYesterday
