Devclass TanStack Considers Invitation-Only Pull Requests After Supply Chain Attack
Article Content
- •TanStack is considering invitation-only pull requests after a supply chain attack.
- •The Shai-Hulud worm exploited GitHub Actions, leading to a cache poisoning incident.
- •TanStack has implemented multiple security measures to mitigate future risks.
The TanStack team is evaluating security measures following a supply chain attack that exploited a GitHub Actions misconfiguration. The Shai-Hulud worm, used by TeamPCP, triggered a pull request that executed malicious code, poisoning a shared cache across the repository. In response, TanStack has removed the vulnerable pull_request_target feature from its CI pipeline and implemented several security enhancements, including disabling caches and pinning actions to commit SHA hashes. A drastic proposal under consideration is making pull requests by invitation only, a significant shift from the open-source model. While this could enhance security, it may deter contributions from the community. The team emphasizes that they will not transition to a closed-source model but may require discussions before PR submissions. The incident highlights broader concerns regarding supply chain security and GitHub's role in cache management.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Shai-Hulud Worm and TanStack in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…