github-actions
Safeguard articles tagged "github-actions" — guides, analysis, and best practices for software supply chain and application security.
66 articles
CI Secret Masking Matches the Exact String, and Almost Nothing Else
Encode it, uppercase it, split it across two log lines, and masking has nothing to match against. This is not a bug in any platform. It is the only mechanism possible without semantic analysis of every command a pipeline runs.
A Self-Hosted Runner Is a Machine on Your Network That Runs Strangers' Code
A hosted runner is destroyed after the job. A self-hosted one persists, on your network, executing code from your repository, and if that repository accepts contributions the code is not always yours.
A Tag Is Not a Version
You deployed myapp:1.4.2 in March and myapp:1.4.2 in September. Those are not necessarily the same image. Almost every tag you rely on is a mutable pointer that someone else can move without telling you.
How a GitHub Actions Flaw Turned a 61-Million-Download Python Package Into a Cryptominer Delivery Vector
The Ultralytics YOLO compromise in December 2024 didn't touch a single line of reviewed code. It exploited the CI/CD pipeline that builds and publishes the package instead.
How a Non-Atomic Credential Rotation Let Attackers Take Over 76 Trivy Action Tags
A compromised-credential attack on Aquasecurity's Trivy scanner force-pushed malware into version tags across trivy-action and setup-trivy, exploiting the gap left by an earlier, incomplete rotation.
The AsyncAPI Hijack: When Trusted Publishing Becomes the Attack Path
On 14 July 2026 attackers used 37 pull requests against a pull_request_target workflow to steal the asyncapi-bot token, then let npm's OIDC trusted publisher automatically ship the malicious release. Four packages, 2.25 million weekly downloads, four hours live — and no code review was bypassed, because none was required.
The tj-actions/changed-files GitHub Action Supply Chain C...
CVE-2025-30066 exposed how a compromised tj-actions/changed-files GitHub Action leaked CI/CD secrets into build logs across 23,000+ repos. Timeline, impact, and fixes.
Securing Secrets and Environment Variables in GitHub Actions
A tag-pinned GitHub Action used by 23,000+ repos was rewritten to dump CI memory in March 2025 — here's how OIDC and SHA-pinning would have stopped it.
Securing Playwright E2E Tests in GitHub Actions Without Leaking Secrets
A 2025 supply-chain attack on tj-actions/changed-files hit 23,000+ repos and dumped secrets into public logs — the same CI patterns power most Playwright pipelines.
Hardening a Java build pipeline in GitHub Actions
23,000+ repos leaked CI secrets when tj-actions/changed-files was hijacked in March 2025. Here's how to pin, OIDC, and sign a Java pipeline against that.
Incident response playbook for a compromised dependency or CI action
23,000+ repos leaked secrets when tj-actions was hijacked in March 2025. Here's the revoke, rotate, and audit playbook for when it's your turn.
CI/CD pipeline hardening against supply chain attacks
23,000+ repos were exposed when tj-actions/changed-files was compromised in March 2025 — pinned SHAs and OIDC would have stopped it cold.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.