EPISODE · Apr 28, 2025 · 32 MIN
tj-actions with Endor Lab's Dimitri Stiliadis
from Open Source Security
Dimitri Stiliadis, CTO from Endor Labs, discusses the recent tj-actions/changed-files supply chain attack, where a compromised GitHub Action exposed CI/CD secrets. We explore the impressive multi-stage attack vector and the broader often-overlooked vulnerabilities in our CI/CD pipelines, emphasizing the need to treat these build systems with production-level security rigor instead of ignoring them. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-04-tjactions_with_dimitri_stiliadis/
NOW PLAYING
tj-actions with Endor Lab's Dimitri Stiliadis
No transcript for this episode yet
Similar Episodes
Feb 18, 2026 ·26m
Jul 24, 2025 ·73m
Nov 3, 2024 ·52m
Sep 26, 2024 ·67m
Sep 16, 2024 ·139m
Aug 14, 2024 ·76m