Primer on GitHub Actions Security - Threat Model, Attacks and Defenses (Part 1/2)
wiz.io | blog | #ai-security | #supply-chain | #github-actions | #ci-cd | #threat-model | #wiz | #trust-boundary | #script-injection
Summary
Part one of a GitHub Actions security primer: the trusted vs untrusted threat model, three risks — PR pwnage, script injection, third-party components — seen in tj-actions, Ultralytics, Trivy.
- Published
- Collected
Skip to content