Safeguard
Tag

github-actions

Safeguard articles tagged "github-actions" — guides, analysis, and best practices for software supply chain and application security.

66 articles

DevSecOps

CI Secret Masking Matches the Exact String, and Almost Nothing Else

Encode it, uppercase it, split it across two log lines, and masking has nothing to match against. This is not a bug in any platform. It is the only mechanism possible without semantic analysis of every command a pipeline runs.

Sep 18, 20266 min read
DevSecOps

A Self-Hosted Runner Is a Machine on Your Network That Runs Strangers' Code

A hosted runner is destroyed after the job. A self-hosted one persists, on your network, executing code from your repository, and if that repository accepts contributions the code is not always yours.

Sep 18, 20265 min read
Software Supply Chain Security

A Tag Is Not a Version

You deployed myapp:1.4.2 in March and myapp:1.4.2 in September. Those are not necessarily the same image. Almost every tag you rely on is a mutable pointer that someone else can move without telling you.

Sep 17, 20265 min read
Security News

How a GitHub Actions Flaw Turned a 61-Million-Download Python Package Into a Cryptominer Delivery Vector

The Ultralytics YOLO compromise in December 2024 didn't touch a single line of reviewed code. It exploited the CI/CD pipeline that builds and publishes the package instead.

Sep 16, 20266 min read
Vulnerability Analysis

How a Non-Atomic Credential Rotation Let Attackers Take Over 76 Trivy Action Tags

A compromised-credential attack on Aquasecurity's Trivy scanner force-pushed malware into version tags across trivy-action and setup-trivy, exploiting the gap left by an earlier, incomplete rotation.

Sep 16, 20265 min read
DevSecOps

The AsyncAPI Hijack: When Trusted Publishing Becomes the Attack Path

On 14 July 2026 attackers used 37 pull requests against a pull_request_target workflow to steal the asyncapi-bot token, then let npm's OIDC trusted publisher automatically ship the malicious release. Four packages, 2.25 million weekly downloads, four hours live — and no code review was bypassed, because none was required.

Jul 28, 20266 min read
DevSecOps

The tj-actions/changed-files GitHub Action Supply Chain C...

CVE-2025-30066 exposed how a compromised tj-actions/changed-files GitHub Action leaked CI/CD secrets into build logs across 23,000+ repos. Timeline, impact, and fixes.

Jul 27, 20268 min read
DevSecOps

Securing Secrets and Environment Variables in GitHub Actions

A tag-pinned GitHub Action used by 23,000+ repos was rewritten to dump CI memory in March 2025 — here's how OIDC and SHA-pinning would have stopped it.

Jul 15, 20266 min read
DevSecOps

Securing Playwright E2E Tests in GitHub Actions Without Leaking Secrets

A 2025 supply-chain attack on tj-actions/changed-files hit 23,000+ repos and dumped secrets into public logs — the same CI patterns power most Playwright pipelines.

Jul 12, 20267 min read
DevSecOps

Hardening a Java build pipeline in GitHub Actions

23,000+ repos leaked CI secrets when tj-actions/changed-files was hijacked in March 2025. Here's how to pin, OIDC, and sign a Java pipeline against that.

Jul 11, 20266 min read
Supply Chain Security

Incident response playbook for a compromised dependency or CI action

23,000+ repos leaked secrets when tj-actions was hijacked in March 2025. Here's the revoke, rotate, and audit playbook for when it's your turn.

Jul 10, 20266 min read
Supply Chain Security

CI/CD pipeline hardening against supply chain attacks

23,000+ repos were exposed when tj-actions/changed-files was compromised in March 2025 — pinned SHAs and OIDC would have stopped it cold.

Jul 10, 20267 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.