What’s New

GitHub — GitHub Actions holds potentially malicious workflows for approval

GitHub Actions holds potentially malicious workflows for approval

Recent supply chain attacks use compromised GitHub credentials to push malicious GitHub Actions workflows that steal CI/CD credentials and carry out additional attacks. To help protect public reposito…

Security
  • GitHub Actions now holds potentially malicious workflows for approval to protect against supply chain attacks that use compromised credentials to push malicious workflows and steal CI/CD credentials
View original