Skip to content

Is 2.3.33 legit?#305

Open
mderriey wants to merge 1 commit intoCheckmarx:mainfrom
mderriey:patch-1
Open

Is 2.3.33 legit?#305
mderriey wants to merge 1 commit intoCheckmarx:mainfrom
mderriey:patch-1

Conversation

@mderriey
Copy link
Copy Markdown

By submitting a PR to this repository, you agree to the terms within the Checkmarx Code of Conduct. Please see the contributing guidelines for how to create and submit a high-quality PR for this repo.

Description

We want to know whether the recent activity on this repository is legit or not:

  1. All our workflows using 2.3.32 are now failing because the releases/tags were deleted from the repo.
  2. A new 2.3.33 version was released, however there's no changelog on GitHub or on https://docs.checkmarx.com/en/34965-332355-github-actions---changelog.html.

We found it suspicious activity, and the recent news (https://thehackernews.com/2026/03/trivy-security-scanner-github-actions.html) mean we want to be cautious before updating.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant