Executive brief
The reviewdog/action-setup GitHub Action was compromised with malicious code that dumps exposed secrets to GitHub Actions Workflow Logs. The supply chain attack affected version v1 and several downstream reviewdog actions that depend on it, regardless of pinning method.
Affected products
- reviewdog action-setup v1
- reviewdog action-shellcheck < 1.29.2
- reviewdog action-composite-template < 0.20.2
- reviewdog action-staticcheck < 1.26.2
- reviewdog action-ast-grep < 1.26.2
- reviewdog action-typos < 1.17.2
Timeline
- 2025-03-11: exploited: Malicious code added to reviewdog/action-setup@v1
- 2025-03-19: disclosed: CVE received from GitHub, Inc.
- 2025-03-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-03-24: advisory: NVD publication date