You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Describe the bug
Hi jq org. Thank you so much for all your hard work. It's very much appreciated.
I looked recently for an install jq github action and was greeted in the github marketplace with official looking actions which are run by single users. In light of the recent tj-actions security events, it would be nice to have an official action to install jq.
Describe the bug
Hi jq org. Thank you so much for all your hard work. It's very much appreciated.
I looked recently for an install jq github action and was greeted in the github marketplace with official looking actions which are run by single users. In light of the recent tj-actions security events, it would be nice to have an official action to install jq.
Here is a search on the marketplace https://github.com/marketplace?query=jq&type=actions
https://github.com/marketplace/actions/install-jq - dcarbone/install-jq-action
https://github.com/marketplace/actions/install-jq-tool - mbround18/install-jq
https://github.com/marketplace/actions/yet-another-setup-jq - vegardit/gha-setup-jq
Of course a workaround is this, but people are more likely to use an action off the shelf like the above which can lead to security risk.
or
The text was updated successfully, but these errors were encountered: