
Deceptive Tags and Impostor Commits: the new attack vector in the software supply chain
In a new example of how the software supply chain remains an attractive vector for the attackers, the verification of GitHub's popular action has been detected. actions-cool / iss…







