logo

The complete GitHub Actions security checklist

ID: bece4a24-bb49-5193-acac-7a0e902e41fc

STIX ID: report--bece4a24-bb49-5193-acac-7a0e902e41fc

Feed Name: Aikido Security's Blog

Threat Score
78/100

Date Published: 2026-05-11

Date Updated: 2026-07-24

...
...

This document is a practical GitHub Actions security checklist that describes how workflow misconfigurations and mutable dependencies have enabled large supply-chain campaigns and targeted exploits; it summarizes observed attacks (e.g., Trivy, tj-actions, Ultralytics, Shai-Hulud), outlines common dangerous patterns (pull_request_target, workflow_run, untrusted interpolation, unpinned actions, long-lived secrets, self-hosted runners), and provides concrete mitigations and tooling recommendations to reduce exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.