Hi Cephers,

Due to the escalating situation in which leaked secrets from a previously compromised GH Action (tj-actions) [1] are used to compromise more popular GH Actions (reviewdog)[2], we have decided to immediately disable all Github Actions in all repositories, except the official GH ones, and the ones under the Ceph organization.

From a preliminary analysis, none of our repos has been impacted. However, given that the Ceph org hosts more that 200 repositories (including forks), it's safer to take a conservative approach while a deeper analysis is undertaken (and the situation settles down).

We know that this might have an immediate impact on Ceph teams, as it will break CI using unofficial Github Actions. The recommendation for each team is to review their Github workflows in their repos (.github/workflows/*.yaml) and ensure that:
We apologize for the inconvenience, but we did this to reduce the exposure of the Ceph community to a series of attacks that may continue to escalate.

Kind Regards,
Ernesto

[1] https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised
[2] https://www.stepsecurity.io/blog/reviewdog-github-actions-are-compromised