https://neciudan.dev/github-actions-poisoning (opens in new tab)
--- title: "GitHub Actions Cache Poisoning is eating open source" publishDate: 2026-05-17T00:00:00.000Z excerpt: "Angular. tj-actions. Cline. TanStack. The same class of attack has been quietly hijacking publish pipelines for two years. Here's what it is, how it works, and what you need to do today." category: "security" tags: ["security", "github", "vulnerability", "open-source"] canonical: --- WHen I write an article, I try as much as possible to make it timeless. Thats why I avoid writin...
Read the original article