VYPR

Pipelines-as-Code

by Tekton

CVEs (1)

  • CVE-2026-54168Aug 20, 2026
    risk 0.00cvss epss

    ### Impact When Pipelines-as-Code is configured with a GitHub App installed across multiple repositories, the installation token issued during webhook processing is not scoped to the triggering repository by default. The token retains access to all repositories in the GitHub App…