mstdn.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A general-purpose Mastodon server with a 500 character limit. All languages are welcome.

Administered by:

Server stats:

7.6K
active users

#GithubAction

0 posts0 participants0 posts today

Quite happy with my release process for sofmani

-> Push updates to git
-> Release Please generates changelog PR
-> When merged, release is created
-> All files are generated & uploaded to release
-> Triggers a dispatch workflow to my OTHER repo, which is the homebrew tap
-> That generates a PR for homebrew update & bottles
-> Add label pr-pull and it updates the tap with the bottles

With tests on every step

🏆 Team12 just won the #Dust AI Agent #Hackathon! 🎉 We developed an innovative #AI agent that can fix functional bugs reported by non-technical users (CSM, PO/PM, etc...), streamlining the process, breaking Team Silos and reducing engineering workload.

🌟 Key Features:
- End-to-end bug fixing without engineer involvement, via a simple interface
- Seamless integration with our knowledge base in @Notion 📚
- Deploy in ephemeral environments thanks to #GitHubAction & #MCP

Security researchers reveal supply chain attack on 'tj-actions/changed-files' #GitHubAction

The attackers added malicious code to the tool on Mar 14, 2025 that dumped secrets to the repository of any projects using the action. The incident has now been assigned CVE-2025-30066. GitHub has now reversed the malicious changes.

GitHub is advising impacted users to rotate secrets, review workflows for unexpected output, and update the Action

#cybersecurity #threatintel

bleepingcomputer.com/news/secu

BleepingComputer · Supply chain attack on popular GitHub Action exposes CI/CD secretsBy Bill Toulas

So this weekend's tj-actions/changed-files credentials stealing fun and games.

I know you can fake git commit time stamps, but it looks like the change was made just before 17:00 GMT on Friday night. I wonder if that was deliberate to try adnd catch people pushing updates on their way out the door and not expecting to check the logs before Monday morning.

Nice to see the OpenSauced pizza-action in action updating the CODEOWNERS file in one of our repositories. The way we're generating it, it's more granular which helps to laser focus on who gets automatically tagged for reviews in PRs.🍕 github.com/open-sauced/pizza-c #github #githubaction #opensource

This is an automated PR generated by the OpenSauced pizza-action.
GitHubchore (automated): OpenSauced updates by github-actions[bot] · Pull Request #166 · open-sauced/pizza-cliBy github-actions[bot]

I came up with a nice #orgmode #hugo #githubaction with nice scripts so I only have to version control my #org files and github handles the rest. Everything seemed to work with the content I already have so I made a test post to ensure that worked too, and it did not. I spent an hour trying to diagnose why the hell this one post wasn't exporting - debugging the workflow on #GitHub, debugging locally, everything.

I had the post dated for the fifth. Today is the fourth. I am certifiably a moron.