Two open-source projects vulnerable to 'GitHub Environment Injection'
Days after Google announced an open source bug bounty program, Legit Security reported supply chain attack vulnerabilities in open-source projects from Google and Apache.
Source: scmagazine.com