TanStack Supply Chain Attack (And How to Lock Down GitHub Actions) | Blog (opens in new tab)
How TanStack got hit through GitHub Actions, the 8 vulnerabilities we found auditing 20 repos the next day, and the playbook we used to fix them all in 4 days.
Read the original article