security1 distinct publisher
An attacker force-pushed 76 of Trivy's 77 action tags to credential-stealing commits
The maintainers date the second wave to March 19, eighteen days after they disclosed the first one and rotated credentials without doing it all at once, and the only action tag that came through clean was one GitHub had already frozen.
Publishers:github.com
Reality
- Evidence74
- Adoption52
- Hype gap−14
- Incentives68