GitHub Actions holds potentially malicious workflows for approval
Recent supply chain attacks use compromised GitHub credentials to push malicious GitHub Actions workflows that steal CI/CD credentials and carry out additional attacks. To help protect public reposito…
Security
- GitHub Actions now holds potentially malicious workflows for approval to protect against supply chain attacks that use compromised credentials to push malicious workflows and steal CI/CD credentials