news.google.com
Hardening GitHub Actions against pwn requests and token theft - Security Boulevardhttps://news.google.com/rss/articles/CBMiogFBVV95cUxNaExhZTd2ZGhvUldRRWdROV9UOWVuY25DejJLV3lPR21WTkhmSnhaMzZvb0cyTmdMLUg5aXNnMVhKQl8yczlKdFhXMWZUbHdaZE9JM2ZVUkpiYjNrdlh2Q29uTk1yMkRlMllnUzM2M0hHaU5YdEhFUGwzWnl6XzNlRW9YXzI1QVZPbXhuN1pDN3VmQjZINDB1Ty1ieWlkcFA3aWc?oc=5Hardening GitHub Actions against pwn requests and token theft Security BoulevardAug 24, 2026 9:22 AM
news.google.com
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection - The Hacker Newshttps://news.google.com/rss/articles/CBMijAFBVV95cUxNem1rQ0FWSmRVSTJRRlBJYWZ5dmFaVlc2QmhfTjRXLWZKT3ZmeURnLWR5Y0FJMWdVM0NnbmZ4c25EcjFuSTZXdlozbXVEUTNJRHNDWEF4QkgzMUt3VmhOMDQzR1NPU3Jjc3U5NFVOOFhyTmp2aGdYOW1HcGhDbVh0cGplOGdTN0oxeVVYbQ?oc=5Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection The Hacker NewsAug 17, 2026 6:44 PM
bing.com
NuGet kills 365-day API keys: GitHub Actions can go keyless, Azure DevOps cannothttp://www.bing.com/news/apiclick.aspx?ref=FexRss&aid=&tid=6a8cfa6688c54e1cad6db53b0b7baa1c&url=https%3A%2F%2Fwww.msn.com%2Fen-us%2Ftechnology%2Fcybersecurity%2Fnuget-kills-365-day-api-keys-github-actions-can-go-keyless-azure-devops-cannot%2Far-AA2aib32&c=10965321245212164971&mkt=en-usNuGet API key expiration 2026: Microsoft caps new NuGet.org API keys at 30 days starting August 17, forcing all existing keys to expire November 1. Developers using GitHub Actions or GitLab CI can ...Aug 17, 2026 4:04 AM
preloop.dev
Show HN: Run your GitHub Actions locally or self-hosted in isolated microvmshttps://preloop.devHey HN. I've been frustrated with Github Actions' reliability, and inability to run workflows locally. Preloop is a Rust reimplementation of the GitHub Actions, both the runner(tracking the latest version) and the control plane that runs in hardware-isolated microvms on MacOS/Linux/Windows(we use smolvm project that uses the libkrun vmm).The microvms starts inAug 9, 2026 7:55 PM
news.google.com
GitHub Actions holds potentially malicious workflows for approval - The GitHub Bloghttps://news.google.com/rss/articles/CBMiqwFBVV95cUxQeXVucVhuYlFRUjczbWhEbGMwcWJBdGR5dU53dHRWR1VWTmM3bjd6a3JNMElXc19NcVBvbjdHTTZLUGVIeUhfUzhMSUVrOTBVbGdmRDFMRXRIcnF5MjFTVHJtQUpab0xiS2NWNERJVERjZmMxUFJhZ2xYWUVVYU14aTV4RnZiWDlYbkpNVEE0TDNOOGhIS2p4N1NtU01HbFpkRUtMaF9pZ1dCRVk?oc=5GitHub Actions holds potentially malicious workflows for approval The GitHub BlogJul 28, 2026 7:00 AM
news.google.com
GitHub Actions Gets Secure-by-Default CI/CD: Backport Shuts the Pwn Request Window - Tech Timeshttps://news.google.com/rss/articles/CBMiyAFBVV95cUxPSDdSclBRa3hOODZyb0pzYVY5WUhuM1hQeWtVSURwZlJxZkxXelN6QzRERkN1V3RTZVpVb0JVNXlmSWM5ckU0MEpBaDdYekJ1TmFfdzJEeTFTbF9NX1pzVjJNZVRpWTFpSzZpbmhWeVpna256T0JpcklrMmJfWlJXUDVodnJma1dXcldjSFdaN05Vdm5jdG9pSlZFbHV3R040QVhMcHAzd21jXzBQb2JGZ0NIOHBhVWZqZkg2MGNoNFFBWGwxSEdhaQ?oc=5GitHub Actions Gets Secure-by-Default CI/CD: Backport Shuts the Pwn Request Window Tech TimesJul 20, 2026 7:00 AM
news.google.com
GitHub Actions Tutorial: CI/CD in 12 Steps, 35 Min [2026] - tech-insider.orghttps://news.google.com/rss/articles/CBMiaEFVX3lxTE9FZjU0Z1BYbHJqZkFMeWZ3Z2tSQVNzVVZhRlJfdDNnV2E2TE9ZRGlHZ25EaGlIbnI0eXFyVnZqVGtlXy14VzZwTkk5WG9RSjMzV01pVE9kUG9KY2hBeTl4MkgwQUxVeUJr?oc=5GitHub Actions Tutorial: CI/CD in 12 Steps, 35 Min [2026] tech-insider.orgJun 30, 2026 7:00 AM
news.google.com
GitHub Actions Updates Checkout to Block Forked Pull Request Supply Chain Attacks in CI/CD Workflows - Rescanahttps://news.google.com/rss/articles/CBMiyAFBVV95cUxNenE4ZERZeHpJN0JwYzZQdk5CNXlBRC1SR1QyQkVpcDNJWFlYNDZscXB4U21UOUptSmcyekZvbTJXMl82MmwwU1FkbkRkU3E2M25xaEJUSF9Yd0JiQWxVVjlyNmlpSG53U0xsVEVuZkk0VGIzaEFlbHBOWXp6d0RCbGk4T2VLYjVhUWR4MTVGU3hyTGtvVXE2TDZjbE03SUZQbjZLQk16Y3NQLUx3QjFXLUZEendubmlzRUVGUEVQYTZGOW5leUxncg?oc=5GitHub Actions Updates Checkout to Block Forked Pull Request Supply Chain Attacks in CI/CD Workflows RescanaJun 25, 2026 7:00 AM
news.google.com
GitHub Actions Supply Chain Flaw Exposes Microsoft and Google to Free-Account Hijack - Tech Timeshttps://news.google.com/rss/articles/CBMizAFBVV95cUxQWjBHZU1EUEp4cll1ZlVNRDFaNEx4Zzlhekx0SlR6VzFaYkQ1Z2ttVTJPTjluS1FnRURlZWJuV3AtVGRLTDNkbTRocXh1VkRMOW5hRzA2Nkg3TUVsMzhPOWY3Y3lHU2hrVVM0MzVFVjA0ZU9aVHI1NFBFZndjRXZNbmZSb3M4VHBMWEJSYmpGQ3ZQakhGc093UVE0TGRjd1Rkckl1T2JYTmpsOWFGTGE0M3RJUDBYZHlvaTRWNDNod3ZIb296S0JsblhsRTk?oc=5GitHub Actions Supply Chain Flaw Exposes Microsoft and Google to Free-Account Hijack Tech TimesJun 25, 2026 7:00 AM
news.google.com
GitHub Actions Enhances CI/CD Security: actions/checkout v7 Blocks Common Pwn Request Attack Patterns - Rescanahttps://news.google.com/rss/articles/CBMiyAFBVV95cUxNdUhkaV9DT1VzT3RmOUowcWxKWGZ3a21RUzVZNl85Y1BVbXpKUXh2R1k5ejJxX19zcjFnOW5GSGxjRmZVMEJZSnU0WWhUQWRZSEhQTEYwMGVaVjRBTG1lWFlIUGh6c011YlRqSzkwclllUEJQU2lodl81WDd0UzV1TFhiYUEyd2tiazFqSFRQU2pILTVwd3B3amdCMUpybFdJcW1QcWw3ZmNWUXlrRnBob2l2bmRPbndXd2VhNGM3QUhDVVowekhTTg?oc=5GitHub Actions Enhances CI/CD Security: actions/checkout v7 Blocks Common Pwn Request Attack Patterns RescanaJun 24, 2026 7:00 AM
news.google.com
Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets - Aikido Securityhttps://news.google.com/rss/articles/CBMiggFBVV95cUxOWEh4T0Jaa2JQTVl2VFQxZy1oTlBxdkNMcVlPZlZmQ3FfbnJxXzl3bnh0M3NNaUNNRlMzdnptbC1jSHBoSEg0YUtaUmNqYTZjVjdta2diOE5sbXFLTURRb1JMbmxmRzdNOVRzTjZJVzlpaTAyQW02NnhvN1J2VHZvZWVB?oc=5Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets Aikido SecurityJun 24, 2026 7:00 AM
news.google.com
GitHub Actions Checkout Update Blocks Workflows Triggered by Malicious pull_request_target - CyberSecurityNewshttps://news.google.com/rss/articles/CBMiekFVX3lxTE1uSG0tVU1nMEctb0Z5aDZtQUxmWnpMaWJ5NGEzVzdwWTc0aEhzUTBQNnFQWnU1OGQ5SFNKNmdGZFJzNzJ4cTk5anQwWFkta2p1RGJ4R21qUTgwSnI5bnJLLWUwTFRudUVRSFVaQ1lVakRqcE9ha1RUeWpR0gF_QVVfeXFMTkFHYkRlZXhMV0tHOGFxOExYbHo1TlpnYjViOVk2bUhiVFdmR1N4WUV5bXNNbWVKcjNaMUk2SWtWZWZDSWJwcU0xSlpLY1RrTlhWVWt3Q1JOZkZMZ01vUUFCaHdZS054QjZ1ZkZQSjJ5Q3N3Skg0M0VodXBlQmhXcw?oc=5GitHub Actions Checkout Update Blocks Workflows Triggered by Malicious pull_request_target CyberSecurityNewsJun 22, 2026 7:00 AM
news.google.com
Control who and what triggers GitHub Actions workflows - The GitHub Bloghttps://news.google.com/rss/articles/CBMinAFBVV95cUxOY1hNRE5mQndCZXpZTGtCUUFQZVhYUmZsZXFlN0pqLVRzRTNESFcxR0FsVTZ4OGlVM2E4dzgyQkpzaUJvSktnaUpFSFFrUXQxMUJvdGVjTzlHbDd3MThGSHBXc3BhenJJU0xMMklXdUZxdFV0U1NwSElROG5xRWZYa3JMby1tYnhFcnhVcjdlLU5vbVEtWkhoMlUyc2c?oc=5Control who and what triggers GitHub Actions workflows The GitHub BlogJun 18, 2026 7:00 AM
news.google.com
Safer pull_request_target defaults for GitHub Actions checkout - The GitHub Bloghttps://news.google.com/rss/articles/CBMipwFBVV95cUxOYjVIalphbTlKZDdkMl9CaEZ6bzB6aU85YzdqOGtQa1kxMFZzNXJIUWxJbW1RcUpGNmxUd29BV2dUeWNJdjh0Z0ctanVSLXlnVlhleWNtcEdyb2Z5LTlfSllxZVEyWnZXemMtRWRiRlAweUxkVWl2cTJjalBaMm9RRVNlZGtTLTFPV3ltQkNZOEExM1YtaWNJam80RnRxZkdNYUUzM3RlTQ?oc=5Safer pull_request_target defaults for GitHub Actions checkout The GitHub BlogJun 18, 2026 7:00 AM
news.google.com
Kaspersky Container Security Introduces New Features to Optimize DevSecOps and Detect GitHub Actions Misconfigurations - Kasperskyhttps://news.google.com/rss/articles/CBMi-AFBVV95cUxQNG9CV2ZGZTdzV3c4TTJEOTVJYk1DQndhM1pWQ1JSOFl4aldqVnRFS2twZUV6MGhNTTdPeFJaeUpoY3hzOXd2c21Yb1FHdFdKWkZpTlZjbTdQSjU3T2ZhMXVhdnhrSVZwMmFwaGE4WjlCQzI0UmE3QU5lemdmMExTbXNYTXFkNU9PcFpkYlZGWkpwLXo5azlZc2xTZldHdWNEVV9NVXV4cGZ0engzWnJnWXdOeEltaW9NZ2hBeFc5d2FYZjV6SGxwZEl1dmswckpjdERfVkJHaDBDeGJCV040bTFJeFlaZnZBV3Rqd1JxWlNveDAxNThFbw?oc=5Kaspersky Container Security Introduces New Features to Optimize DevSecOps and Detect GitHub Actions Misconfigurations KasperskyJun 17, 2026 7:00 AM
github.com
Show HN: Write Your GitHub Actions in TypeScripthttps://github.com/dedalus-labs/hollywoodI spend a lot of my time writing GitHub Actions.Specifically, I need to script a ton of things. The current way of writing GitHub Actions with YAML is usually fine for small jobs. But for anything complicated, I often find myself in incredibly cursed "shell-in-YAML" situations.This was a major source of bugs for me. Since the "script" was written in YAML, there was actually not an easy way to modularize out the scripting logic to unit test them. Worse, there was zero type safety! For those who work with GitHub Actions frequently, you know how annoying this gets.My ideal GitHub Actions workflow would be to write actual programs, preferably in a language with strong types support.I also don't want an opinionated framework or a beefy runtime to "run" my GitHub Actions. I literally just want a way to write arbitrary programs that can call other services using native tooling from their respective ecosystems; for example, the AWS SDK to orchestrate my cloud.So this got me thinking about the Jun 16, 2026 7:36 PM
news.google.com
Securing CI/CD in an agentic world: Claude Code Github action case - Microsofthttps://news.google.com/rss/articles/CBMivAFBVV95cUxNREJ4Wm45a0lId2d5MUxEOHdRWldESTBfVUZWNFdzMWozbGpLVFVNaEVIV0JlZUFBU0ZjMmFCeWNMazVuM1BsNUx2Z3VlajhHQURuR3cyNDd0LTY5YVJsVGpOU0E1RmtsZmVyb1JyOEgyQmNCeFJZT3U5bTBPSlZuNmdtdm10bzNwSmhyMmNLNkRrUU5EYVRxVG1McjVJSmNqZTBTb0dmRk15UlJtOWFubl9TTFRMUnJmQm5MTg?oc=5Securing CI/CD in an agentic world: Claude Code Github action case MicrosoftJun 5, 2026 7:00 AM
news.google.com
Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories - The Hacker Newshttps://news.google.com/rss/articles/CBMigwFBVV95cUxPYnZxN1VTeWJSMVFSS19tazFLdm9vSFh1ZHVXcUxOQjNjX0FpVU4xYldUZ0pJbGRXem5pZEhjVkg5N0ZuR096ZjZ4T0Z1bDFUemI3aVFrRVNZZmJXOVpRZDlHbExMdXZvNHRsanZ5U1JYeHJ0ZUpsNkNZUF83WUF3VC1XSQ?oc=5Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories The Hacker NewsJun 4, 2026 7:00 AM
news.google.com
Popular GitHub Action Tags Redirected to Imposter Commit to Steal CI/CD Credentials - The Hacker Newshttps://news.google.com/rss/articles/CBMifkFVX3lxTE4zbjFRdHJaaDJ1VjFzcHVEd21Yd3M1aDFEaFRIcktIUFU4Wm03eTNNc3gwY25BMUJFaHNlaUxPaENoOTJfbHZJckNXT0ZILXBsdFVIcjQ1REVURy1zaXdDZ2szNDZ5UVU5b04zakk5dlVlc2RaV3JZNFFRQW1RZw?oc=5Popular GitHub Action Tags Redirected to Imposter Commit to Steal CI/CD Credentials The Hacker NewsMay 19, 2026 7:00 AM
news.google.com
actions-cool/issues-helper GitHub Action Compromised: All Tags Point to Imposter Commit That Exfiltrates CI/CD Credentials - StepSecurityhttps://news.google.com/rss/articles/CBMi6gFBVV95cUxQNXFfNnBXWEVBQmpMOHhMN1pOTzdBVlVDRkZLd0p4UnN2UTlldVh3LXo0NXRVRXl5LUR4TldpMGlrSnBDcDBaRnVYenpFdTJEUWVhb2pzWm40MEFZMmtXVU5QOWFObGRaTVh4ZzM4MFA5X1haN0Vlb0dJQ2lGNmRUcVFpb2d5Nnl3Q0JocGExeE5HUW9LTnp1RmlFcDZ4NXJYR0Rfdk03VVU4V3Y4QlpxZXNnRlc5Qm9vYkQ4TG1JdHlteWtaTmdjVkZURVoySDBSWGd5R1V1RU5INzBpUXlVb3BlQWdpZC1ZaVE?oc=5actions-cool/issues-helper GitHub Action Compromised: All Tags Point to Imposter Commit That Exfiltrates CI/CD Credentials StepSecurityMay 18, 2026 7:00 AM