Skip to content

Support GitHub Actions for release build#1238

Merged
glensc merged 8 commits intoeventum:masterfrom
glensc:gh-release
Dec 28, 2022
Merged

Support GitHub Actions for release build#1238
glensc merged 8 commits intoeventum:masterfrom
glensc:gh-release

Conversation

@glensc
Copy link
Copy Markdown
Member

@glensc glensc commented Oct 19, 2021

@glensc glensc added this to the 3.10.8 milestone Oct 19, 2021
@glensc glensc self-assigned this Oct 19, 2021
@glensc glensc modified the milestones: 3.10.8, 3.10.9 Nov 10, 2021
@glensc glensc marked this pull request as ready for review September 25, 2022 15:15
@glensc glensc force-pushed the gh-release branch 2 times, most recently from a6f2100 to 3fb9680 Compare September 25, 2022 21:34
@glensc
Copy link
Copy Markdown
Member Author

glensc commented Dec 8, 2022

This ncipollo/release-action@v1 action caused github support to revoke all my tokens and reset password due suspicious activity.

Hi glensc,

We’re writing to let you know that we observed suspicious activity that suggests a threat actor used a Personal Access Token (PAT) associated with your account to access private repository metadata.

Out of an abundance of caution, we reset your account password and revoked all of your Personal Access Tokens (classic), OAuth App tokens, and GitHub App tokens to protect your account, glensc.

  • What happened *

We do not believe the attacker obtained these tokens via a compromise of GitHub or its systems, because the tokens in question are not stored by GitHub in their original, usable formats. At this time, evidence suggests that the threat actor used compromised tokens to access private repository metadata. You can review an example of repository metadata in the example response here:

https://docs.github.com/en/rest/repos/repos?apiVersion=2022-11-28#list-repositories-for-a-user--code-samples

The following tokens were identified:

automatic releases for eventum/eventum

@glensc glensc added this to the 3.10.12 milestone Dec 28, 2022
Skip release creation on non-tags

Extract release note from the tag

Use env to simplify reading
@glensc glensc merged commit 364c7a2 into eventum:master Dec 28, 2022
@glensc glensc deleted the gh-release branch December 28, 2022 23:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant