TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Show HN: Scharf – Find and protect ur GitHub Actions from supply-chain attacks

1 pointsby nyellabout 2 months ago
Welcome to &quot;Scharf&quot;, a blazing-fast security scanner for hardening third-party GitHub actions with mutable references. Using mutable references (version tags, main&#x2F;master&#x2F;dev etc.) is a security vulnerability that can result in supply-chain attacks.<p>The recent `tj-actions&#x2F;changed-files` security incident is scary, so we built a mutable-reference scanner that performs a deep scan across branches to identify all third-party GitHub actions used in organization Git projects. The output report can be exported to CSV or JSON (default).<p>Try it out!

no comments

no comments