logoalt Hacker News

Rial_Labstoday at 2:05 AM0 repliesview on HN

You're right and forking actions is the correct mitigation.

The gap is operational discipline. Most teams know they should fork upstream actions and review updates before pulling them in. Almost none actually do it consistently. The Trivy attack is useful not because it revealed something unknown but because it made the abstract cost of that gap concrete.