It would appear as if Wiz may have discovered another supply-chain compromise:
The attack involved compromising the v1 tag of reviewdog/action-setup between March 11th 18:42 and 20:31 UTC. Unlike the tj-actions attack that used curl to retrieve a payload, this attack directly inserted a base64-encoded malicious payload into the file. When executed, the code dumped CI runner memory containing workflow secrets, which were then visible in logs as double-encoded base64 strings. The attack chain appears to have started with the compromise of reviewdog/action-setup, which was then used to compromise the tj-actions-bot Personal Access Token (PAT), ultimately leading to the compromise of tj-actions/changed-files. Organizations are advised to check for affected repositories using GitHub queries, examine workflow logs for evidence of compromise, rotate any leaked secrets, and implement preventive measures like pinning actions to specific commit hashes rather than version tags.
Ontem eu postei aqui sobre os compiladores da AMD que podem ser baixados gratuitamente: C, C++ e Fortran.
Hoje eu instalei e testei.
A instalação não podia ser mais simples, lembra os velhos tempos:
1) Se extrai o conteúdo do tar.xz onde se deseja colocar os compiladores.
2) Roda-se o que configura um arquivo com o paths para LD_LIBRARY_PATH e PATH
e pronto. Não tem nada de apt que joga as coisas dentro dos diretórios do sistema. Lembra o tempo que se usava o /usr/local no Linux
that lasted until she couldn't get on the wifi. pretty sure her wifi card shit the bed so I gave her my usb wifi dongle. it didn't automatically configure the driver so I pulled out the little disc that came with it. the disc also didn't install the driver automatically. there was a linux folder on it containing presumably everything I needed, but when running the she couldn't type her password into the terminal. my brother brought her a windows surface and she gave up immediately
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.