Skip to content

Commit 2899d9e

Browse files
Remove pr-add-reviewers.yml (auto-add of compromised account) (#1492)
The workflow's only step hard-coded `cx-plugins-releases` as a PR reviewer. That account ("AST Sypher", astsypher@checkmarx.com) appears compromised by the Mini Shai-Hulud supply-chain worm: on 2026-05-09 it created 11 public Dune-themed repos containing exfiltrated secrets in results/ directories (one ~52 MB), and the same day a rogue version 2026.5.09 of the checkmarx-ast-scanner Jenkins plugin was published outside the release pipeline. Removing the static reference until Security/IR completes the rotation and a clean replacement reviewer is decided.
1 parent c2eb0f5 commit 2899d9e

1 file changed

Lines changed: 0 additions & 22 deletions

File tree

.github/workflows/pr-add-reviewers.yml

Lines changed: 0 additions & 22 deletions
This file was deleted.

0 commit comments

Comments
 (0)