Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Primer on GitHub Actions Security - Threat Model, Attacks and Defenses (Part 1/2)

Summary

Part one of a GitHub Actions security primer: the trusted vs untrusted threat model, three risks — PR pwnage, script injection, third-party components — seen in tj-actions, Ultralytics, Trivy.
Published
Collected

original ↗

Related coverage

back