Skip to content

ci(dadwadw233-vibeportrait): refresh HOL workflow action refs#3

Closed
internet-dot wants to merge 1 commit into
dadwadw233:mainfrom
internet-dot:ci/refresh-hol-workflows-20260407182156
Closed

ci(dadwadw233-vibeportrait): refresh HOL workflow action refs#3
internet-dot wants to merge 1 commit into
dadwadw233:mainfrom
internet-dot:ci/refresh-hol-workflows-20260407182156

Conversation

@internet-dot

@internet-dot internet-dot commented Apr 7, 2026

Copy link
Copy Markdown

This refreshes the pinned HOL workflow action refs already present in the repo.

Updated workflow refs:

  • the scanner workflow file: HOL ai-plugin-scanner action pin -> HOL ai-plugin-scanner action pin

It only updates the existing workflow action pin(s), does not change runtime code, and does not add secrets or publish behavior.

@internet-dot internet-dot force-pushed the ci/refresh-hol-workflows-20260407182156 branch from 9e9d051 to 193688c Compare April 7, 2026 19:12
@internet-dot internet-dot changed the title ci: refresh HOL workflow action refs ci(dadwadw233-vibeportrait): refresh HOL workflow action refs Apr 7, 2026
@dadwadw233

Copy link
Copy Markdown
Owner

Closing as part of response to the coordinated supply chain attack documented at TickTockBent/charlotte#143

The @internet-dot account is a confirmed campaign operator that has submitted this pattern of PRs to 200+ MCP-related repos. The original workflow (introduced by PR #1) has already been removed in commit c021ebf.

This 'refresh action refs' PR is the documented follow-up vector: bump the pinned SHA to a new action commit, through which the attacker can ship modified code to any repo that merged the initial PR. Not merging.

@dadwadw233 dadwadw233 closed this Apr 8, 2026
@internet-dot internet-dot deleted the ci/refresh-hol-workflows-20260407182156 branch April 9, 2026 12:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants