189 results for github action (8.167 seconds)

news.google.com
Hardening GitHub Actions against pwn requests and token theft - Security Boulevardhttps://news.google.com/rss/articles/CBMiogFBVV95cUxNaExhZTd2ZGhvUldRRWdROV9UOWVuY25DejJLV3lPR21WTkhmSnhaMzZvb0cyTmdMLUg5aXNnMVhKQl8yczlKdFhXMWZUbHdaZE9JM2ZVUkpiYjNrdlh2Q29uTk1yMkRlMllnUzM2M0hHaU5YdEhFUGwzWnl6XzNlRW9YXzI1QVZPbXhuN1pDN3VmQjZINDB1Ty1ieWlkcFA3aWc?oc=5Hardening GitHub Actions against pwn requests and token theft Security Boulevard
Aug 24, 2026 9:22 AM
bing.com
NuGet kills 365-day API keys: GitHub Actions can go keyless, Azure DevOps cannothttp://www.bing.com/news/apiclick.aspx?ref=FexRss&aid=&tid=6a8cfa6688c54e1cad6db53b0b7baa1c&url=https%3A%2F%2Fwww.msn.com%2Fen-us%2Ftechnology%2Fcybersecurity%2Fnuget-kills-365-day-api-keys-github-actions-can-go-keyless-azure-devops-cannot%2Far-AA2aib32&c=10965321245212164971&mkt=en-usNuGet API key expiration 2026: Microsoft caps new NuGet.org API keys at 30 days starting August 17, forcing all existing keys to expire November 1. Developers using GitHub Actions or GitLab CI can ...
Aug 17, 2026 4:04 AM
preloop.dev
Show HN: Run your GitHub Actions locally or self-hosted in isolated microvmshttps://preloop.devHey HN. I've been frustrated with Github Actions' reliability, and inability to run workflows locally. Preloop is a Rust reimplementation of the GitHub Actions, both the runner(tracking the latest version) and the control plane that runs in hardware-isolated microvms on MacOS/Linux/Windows(we use smolvm project that uses the libkrun vmm).The microvms starts in
Aug 9, 2026 7:55 PM
news.google.com
GitHub Actions holds potentially malicious workflows for approval - The GitHub Bloghttps://news.google.com/rss/articles/CBMiqwFBVV95cUxQeXVucVhuYlFRUjczbWhEbGMwcWJBdGR5dU53dHRWR1VWTmM3bjd6a3JNMElXc19NcVBvbjdHTTZLUGVIeUhfUzhMSUVrOTBVbGdmRDFMRXRIcnF5MjFTVHJtQUpab0xiS2NWNERJVERjZmMxUFJhZ2xYWUVVYU14aTV4RnZiWDlYbkpNVEE0TDNOOGhIS2p4N1NtU01HbFpkRUtMaF9pZ1dCRVk?oc=5GitHub Actions holds potentially malicious workflows for approval The GitHub Blog
Jul 28, 2026 7:00 AM
news.google.com
GitHub Actions Gets Secure-by-Default CI/CD: Backport Shuts the Pwn Request Window - Tech Timeshttps://news.google.com/rss/articles/CBMiyAFBVV95cUxPSDdSclBRa3hOODZyb0pzYVY5WUhuM1hQeWtVSURwZlJxZkxXelN6QzRERkN1V3RTZVpVb0JVNXlmSWM5ckU0MEpBaDdYekJ1TmFfdzJEeTFTbF9NX1pzVjJNZVRpWTFpSzZpbmhWeVpna256T0JpcklrMmJfWlJXUDVodnJma1dXcldjSFdaN05Vdm5jdG9pSlZFbHV3R040QVhMcHAzd21jXzBQb2JGZ0NIOHBhVWZqZkg2MGNoNFFBWGwxSEdhaQ?oc=5GitHub Actions Gets Secure-by-Default CI/CD: Backport Shuts the Pwn Request Window Tech Times
Jul 20, 2026 7:00 AM
news.google.com
GitHub Actions Updates Checkout to Block Forked Pull Request Supply Chain Attacks in CI/CD Workflows - Rescanahttps://news.google.com/rss/articles/CBMiyAFBVV95cUxNenE4ZERZeHpJN0JwYzZQdk5CNXlBRC1SR1QyQkVpcDNJWFlYNDZscXB4U21UOUptSmcyekZvbTJXMl82MmwwU1FkbkRkU3E2M25xaEJUSF9Yd0JiQWxVVjlyNmlpSG53U0xsVEVuZkk0VGIzaEFlbHBOWXp6d0RCbGk4T2VLYjVhUWR4MTVGU3hyTGtvVXE2TDZjbE03SUZQbjZLQk16Y3NQLUx3QjFXLUZEendubmlzRUVGUEVQYTZGOW5leUxncg?oc=5GitHub Actions Updates Checkout to Block Forked Pull Request Supply Chain Attacks in CI/CD Workflows Rescana
Jun 25, 2026 7:00 AM
news.google.com
GitHub Actions Supply Chain Flaw Exposes Microsoft and Google to Free-Account Hijack - Tech Timeshttps://news.google.com/rss/articles/CBMizAFBVV95cUxQWjBHZU1EUEp4cll1ZlVNRDFaNEx4Zzlhekx0SlR6VzFaYkQ1Z2ttVTJPTjluS1FnRURlZWJuV3AtVGRLTDNkbTRocXh1VkRMOW5hRzA2Nkg3TUVsMzhPOWY3Y3lHU2hrVVM0MzVFVjA0ZU9aVHI1NFBFZndjRXZNbmZSb3M4VHBMWEJSYmpGQ3ZQakhGc093UVE0TGRjd1Rkckl1T2JYTmpsOWFGTGE0M3RJUDBYZHlvaTRWNDNod3ZIb296S0JsblhsRTk?oc=5GitHub Actions Supply Chain Flaw Exposes Microsoft and Google to Free-Account Hijack Tech Times
Jun 25, 2026 7:00 AM
news.google.com
GitHub Actions Enhances CI/CD Security: actions/checkout v7 Blocks Common Pwn Request Attack Patterns - Rescanahttps://news.google.com/rss/articles/CBMiyAFBVV95cUxNdUhkaV9DT1VzT3RmOUowcWxKWGZ3a21RUzVZNl85Y1BVbXpKUXh2R1k5ejJxX19zcjFnOW5GSGxjRmZVMEJZSnU0WWhUQWRZSEhQTEYwMGVaVjRBTG1lWFlIUGh6c011YlRqSzkwclllUEJQU2lodl81WDd0UzV1TFhiYUEyd2tiazFqSFRQU2pILTVwd3B3amdCMUpybFdJcW1QcWw3ZmNWUXlrRnBob2l2bmRPbndXd2VhNGM3QUhDVVowekhTTg?oc=5GitHub Actions Enhances CI/CD Security: actions/checkout v7 Blocks Common Pwn Request Attack Patterns Rescana
Jun 24, 2026 7:00 AM
news.google.com
GitHub Actions Checkout Update Blocks Workflows Triggered by Malicious pull_request_target - CyberSecurityNewshttps://news.google.com/rss/articles/CBMiekFVX3lxTE1uSG0tVU1nMEctb0Z5aDZtQUxmWnpMaWJ5NGEzVzdwWTc0aEhzUTBQNnFQWnU1OGQ5SFNKNmdGZFJzNzJ4cTk5anQwWFkta2p1RGJ4R21qUTgwSnI5bnJLLWUwTFRudUVRSFVaQ1lVakRqcE9ha1RUeWpR0gF_QVVfeXFMTkFHYkRlZXhMV0tHOGFxOExYbHo1TlpnYjViOVk2bUhiVFdmR1N4WUV5bXNNbWVKcjNaMUk2SWtWZWZDSWJwcU0xSlpLY1RrTlhWVWt3Q1JOZkZMZ01vUUFCaHdZS054QjZ1ZkZQSjJ5Q3N3Skg0M0VodXBlQmhXcw?oc=5GitHub Actions Checkout Update Blocks Workflows Triggered by Malicious pull_request_target CyberSecurityNews
Jun 22, 2026 7:00 AM
news.google.com
Control who and what triggers GitHub Actions workflows - The GitHub Bloghttps://news.google.com/rss/articles/CBMinAFBVV95cUxOY1hNRE5mQndCZXpZTGtCUUFQZVhYUmZsZXFlN0pqLVRzRTNESFcxR0FsVTZ4OGlVM2E4dzgyQkpzaUJvSktnaUpFSFFrUXQxMUJvdGVjTzlHbDd3MThGSHBXc3BhenJJU0xMMklXdUZxdFV0U1NwSElROG5xRWZYa3JMby1tYnhFcnhVcjdlLU5vbVEtWkhoMlUyc2c?oc=5Control who and what triggers GitHub Actions workflows The GitHub Blog
Jun 18, 2026 7:00 AM
news.google.com
Safer pull_request_target defaults for GitHub Actions checkout - The GitHub Bloghttps://news.google.com/rss/articles/CBMipwFBVV95cUxOYjVIalphbTlKZDdkMl9CaEZ6bzB6aU85YzdqOGtQa1kxMFZzNXJIUWxJbW1RcUpGNmxUd29BV2dUeWNJdjh0Z0ctanVSLXlnVlhleWNtcEdyb2Z5LTlfSllxZVEyWnZXemMtRWRiRlAweUxkVWl2cTJjalBaMm9RRVNlZGtTLTFPV3ltQkNZOEExM1YtaWNJam80RnRxZkdNYUUzM3RlTQ?oc=5Safer pull_request_target defaults for GitHub Actions checkout The GitHub Blog
Jun 18, 2026 7:00 AM
news.google.com
Kaspersky Container Security Introduces New Features to Optimize DevSecOps and Detect GitHub Actions Misconfigurations - Kasperskyhttps://news.google.com/rss/articles/CBMi-AFBVV95cUxQNG9CV2ZGZTdzV3c4TTJEOTVJYk1DQndhM1pWQ1JSOFl4aldqVnRFS2twZUV6MGhNTTdPeFJaeUpoY3hzOXd2c21Yb1FHdFdKWkZpTlZjbTdQSjU3T2ZhMXVhdnhrSVZwMmFwaGE4WjlCQzI0UmE3QU5lemdmMExTbXNYTXFkNU9PcFpkYlZGWkpwLXo5azlZc2xTZldHdWNEVV9NVXV4cGZ0engzWnJnWXdOeEltaW9NZ2hBeFc5d2FYZjV6SGxwZEl1dmswckpjdERfVkJHaDBDeGJCV040bTFJeFlaZnZBV3Rqd1JxWlNveDAxNThFbw?oc=5Kaspersky Container Security Introduces New Features to Optimize DevSecOps and Detect GitHub Actions Misconfigurations Kaspersky
Jun 17, 2026 7:00 AM
github.com
Show HN: Write Your GitHub Actions in TypeScripthttps://github.com/dedalus-labs/hollywoodI spend a lot of my time writing GitHub Actions.Specifically, I need to script a ton of things. The current way of writing GitHub Actions with YAML is usually fine for small jobs. But for anything complicated, I often find myself in incredibly cursed "shell-in-YAML" situations.This was a major source of bugs for me. Since the "script" was written in YAML, there was actually not an easy way to modularize out the scripting logic to unit test them. Worse, there was zero type safety! For those who work with GitHub Actions frequently, you know how annoying this gets.My ideal GitHub Actions workflow would be to write actual programs, preferably in a language with strong types support.I also don't want an opinionated framework or a beefy runtime to "run" my GitHub Actions. I literally just want a way to write arbitrary programs that can call other services using native tooling from their respective ecosystems; for example, the AWS SDK to orchestrate my cloud.So this got me thinking about the
Jun 16, 2026 7:36 PM
news.google.com
Securing CI/CD in an agentic world: Claude Code Github action case - Microsofthttps://news.google.com/rss/articles/CBMivAFBVV95cUxNREJ4Wm45a0lId2d5MUxEOHdRWldESTBfVUZWNFdzMWozbGpLVFVNaEVIV0JlZUFBU0ZjMmFCeWNMazVuM1BsNUx2Z3VlajhHQURuR3cyNDd0LTY5YVJsVGpOU0E1RmtsZmVyb1JyOEgyQmNCeFJZT3U5bTBPSlZuNmdtdm10bzNwSmhyMmNLNkRrUU5EYVRxVG1McjVJSmNqZTBTb0dmRk15UlJtOWFubl9TTFRMUnJmQm5MTg?oc=5Securing CI/CD in an agentic world: Claude Code Github action case Microsoft
Jun 5, 2026 7:00 AM
news.google.com
actions-cool/issues-helper GitHub Action Compromised: All Tags Point to Imposter Commit That Exfiltrates CI/CD Credentials - StepSecurityhttps://news.google.com/rss/articles/CBMi6gFBVV95cUxQNXFfNnBXWEVBQmpMOHhMN1pOTzdBVlVDRkZLd0p4UnN2UTlldVh3LXo0NXRVRXl5LUR4TldpMGlrSnBDcDBaRnVYenpFdTJEUWVhb2pzWm40MEFZMmtXVU5QOWFObGRaTVh4ZzM4MFA5X1haN0Vlb0dJQ2lGNmRUcVFpb2d5Nnl3Q0JocGExeE5HUW9LTnp1RmlFcDZ4NXJYR0Rfdk03VVU4V3Y4QlpxZXNnRlc5Qm9vYkQ4TG1JdHlteWtaTmdjVkZURVoySDBSWGd5R1V1RU5INzBpUXlVb3BlQWdpZC1ZaVE?oc=5actions-cool/issues-helper GitHub Action Compromised: All Tags Point to Imposter Commit That Exfiltrates CI/CD Credentials StepSecurity
May 18, 2026 7:00 AM