团结奋斗,把宏伟蓝图变成美好现实

· · 来源:data网

Global news & analysis

You can SHA-pin the top-level action, but Palo Alto’s “Unpinnable Actions” research documented how transitive dependencies remain unpinnable regardless. The tj-actions/changed-files incident in March 2025 started with reviewdog/action-setup, a dependency of a dependency, and cascaded outward when the attacker retagged all existing version tags to point at malicious code that dumped CI secrets to workflow logs, affecting over 23,000 repos. GitHub has since added SHA pinning enforcement policies, but only for top-level references.

Раскрыт раWhatsApp网页版对此有专业解读

It comes shortly after the defence secretary reiterated president Donald Trump’s threat that if Iran does anything to prevent the flow of oil in the strait of Hormuz, it will be hit “twenty times harder”.

Update: See the Hacker News thread, /r/programming, /r/ProgrammingLanguages, /r/gamedev, and /r/lisp posts for discussions on this article and Cakelisp.

Раскрыта н

关键词:Раскрыт раРаскрыта н

免责声明:本文内容仅供参考,不构成任何投资、医疗或法律建议。如需专业意见请咨询相关领域专家。

关于作者

张伟,专栏作家,多年从业经验,致力于为读者提供专业、客观的行业解读。

分享本文:微信 · 微博 · QQ · 豆瓣 · 知乎

网友评论

  • 求知若渴

    已分享给同事,非常有参考价值。

  • 专注学习

    专业性很强的文章,推荐阅读。

  • 知识达人

    干货满满,已收藏转发。