Artwork

tj-actions with Endor Lab's Dimitri Stiliadis

Open Source Security

395 subscribers

published

iconShare
 
Manage episode 479477494 series 1502626
Content provided by Open Source Security and Josh Bressers. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Open Source Security and Josh Bressers or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://staging.podcastplayer.com/legal.

Dimitri Stiliadis, CTO from Endor Labs, discusses the recent tj-actions/changed-files supply chain attack, where a compromised GitHub Action exposed CI/CD secrets. We explore the impressive multi-stage attack vector and the broader often-overlooked vulnerabilities in our CI/CD pipelines, emphasizing the need to treat these build systems with production-level security rigor instead of ignoring them.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-04-tjactions_with_dimitri_stiliadis/

  continue reading

488 episodes