Strong opinion:
If it's supply chain and it's "patched" but there's no report or indication of how it happened, AND you have the luxury of replacing it... maybe just replace it.
tj-actions was popular but it's far from the only option.

Comments