reviewdog — action-setup GitHub Action — reviewdog action-setup GitHub Action contains an embedded malicious code vulnerability that dumps exposed secrets to Github Actions Workflow Logs.
Details
EPSS Score
ⓘ
2.30%
81.6th percentile
Confidence
100%
CISA KEV
Date Added
Mar 24, 2025
Patch Due
Apr 14, 2025
Required Action
Apply mitigations as set forth in the CISA instructions linked below. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.