tj-actions with Endor Lab's Dimitri Stiliadis episode artwork

EPISODE · Apr 28, 2025 · 32 MIN

tj-actions with Endor Lab's Dimitri Stiliadis

from Open Source Security

Dimitri Stiliadis, CTO from Endor Labs, discusses the recent tj-actions/changed-files supply chain attack, where a compromised GitHub Action exposed CI/CD secrets. We explore the impressive multi-stage attack vector and the broader often-overlooked vulnerabilities in our CI/CD pipelines, emphasizing the need to treat these build systems with production-level security rigor instead of ignoring them.   The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-04-tjactions_with_dimitri_stiliadis/

Episode metadata supplied by the publisher feed · Published Apr 28, 2025

Embed this episode

Ready to play

tj-actions with Endor Lab's Dimitri Stiliadis

0:00 32:39

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of Open Source Security?

This episode is 32 minutes long.

When was this Open Source Security episode published?

This episode was published on April 28, 2025.

Can I download this Open Source Security episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!