<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: zhenjing</title><link>https://news.ycombinator.com/user?id=zhenjing</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 27 Apr 2026 16:16:39 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=zhenjing" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by zhenjing in "Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign"]]></title><description><![CDATA[
<p>I made a scanner(ActionPin) for the workflow patterns this compromise exposed.<p>ActionPin — a GitHub Actions hardening checker that flags unpinned third-party actions, overbroad workflow permissions, install scripts that touch secrets, and agent-triggered jobs that can reach production credentials.
ActionPin host on github.</p>
]]></description><pubDate>Sat, 25 Apr 2026 08:46:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=47899812</link><dc:creator>zhenjing</dc:creator><comments>https://news.ycombinator.com/item?id=47899812</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47899812</guid></item></channel></rss>