Commit 2899d9e
authored
Remove pr-add-reviewers.yml (auto-add of compromised account) (#1492)
The workflow's only step hard-coded `cx-plugins-releases` as a PR
reviewer. That account ("AST Sypher", astsypher@checkmarx.com) appears
compromised by the Mini Shai-Hulud supply-chain worm: on 2026-05-09 it
created 11 public Dune-themed repos containing exfiltrated secrets in
results/ directories (one ~52 MB), and the same day a rogue version
2026.5.09 of the checkmarx-ast-scanner Jenkins plugin was published
outside the release pipeline.
Removing the static reference until Security/IR completes the rotation
and a clean replacement reviewer is decided.1 parent c2eb0f5 commit 2899d9e
1 file changed
Lines changed: 0 additions & 22 deletions
This file was deleted.
0 commit comments