What's Changed
-
A new option,
disable-sudo-and-containers
, is now available to replace thedisable-sudo policy
, addressing Docker-based privilege escalation (CVE-2025-32955). More details can be found in this blog post. -
New detections have been added based on insights from the tj-actions and reviewdog actions incidents.
Full Changelog: v2...v2.12.0