GitHub's supply chain defense map catalogs nine shipped controls across npm and GitHub Actions — covering pwn-request ...
Attackers abuse compromised GitHub repos and hosted runners to target cPanel and WHM via CVE-2026-41940, using 583 workflows ...
Docker Hub OIDC connections for GitHub Actions replace stored personal access tokens with per-run credentials that expire ...
GitHub Actions will hold potentially malicious workflows until a collaborator with write access approves them.
The proof of concept shows it's possible to upload malicious PyTorch releases to GitHub by exploiting insecure misconfigurations in GitHub Actions. A pair of security researchers managed to infiltrate ...