Improve the Actions workflows #32554
jessehouwing
started this conversation in
General
Replies: 1 comment
-
|
Now with a extensive blog post explaining each possible remediation: https://jessehouwing.net/github-actions-learnings-from-the-recent-nx-hack/ |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
After the security issues from the past days, I took a look at the Actions infrastructure and was wondering whether you'd want some support. A quick read of the disclosure indicates a number of potential things that would be helpful to prevent similar issues in the future.
I'd love to help out here...
Things that immediately spring to mind:
pull_request_targetto Secret Scanning as a push protection pattern.Beta Was this translation helpful? Give feedback.
All reactions