TanStack Considers Invitation-Only Pull Requests After Supply Chain Attack

TanStack Considers Invitation-Only Pull Requests After Supply Chain Attack

First seen 19 May 2026, 15:23 UTC TheregisterDevclass 100% similarity 67.5

Article Content

Browse articles
ThreatCluster

The TanStack team is evaluating security measures following a supply chain attack that exploited a GitHub Actions misconfiguration. The Shai-Hulud worm, used by TeamPCP, triggered a pull request that executed malicious code, poisoning a shared cache across the repository. In response, TanStack has removed the vulnerable pull_request_target feature from its CI pipeline and implemented several security enhancements, including disabling caches and pinning actions to commit SHA hashes. A drastic proposal under consideration is making pull requests by invitation only, a significant shift from the open-source model. While this could enhance security, it may deter contributions from the community. The team emphasizes that they will not transition to a closed-source model but may require discussions before PR submissions. The incident highlights broader concerns regarding supply chain security and GitHub's role in cache management.

Key Points: • TanStack is considering invitation-only pull requests after a supply chain attack. • The Shai-Hulud worm exploited GitHub Actions, leading to a cache poisoning incident. • TanStack has implemented multiple security measures to mitigate future risks.

ThreatCluster AI

Timeline

2026-05-12
Supply chain attack occurred
The Shai-Hulud worm exploited a GitHub Actions misconfiguration, impacting TanStack's repository.
The Register
2026-05-18
TanStack announces security measures
The team outlined steps taken post-attack, including removing vulnerable features and enhancing security protocols.
The Register
2026-05-19
Discussion on invitation-only PRs
TanStack is considering making pull requests by invitation only to prevent future attacks, while maintaining an open-source ethos.
Devclass

Community

Browse all →