GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns
ID: 075bca86-9696-5041-a208-22b1a7af8ba9
STIX ID: report--075bca86-9696-5041-a208-22b1a7af8ba9
Feed Name: CosmicBytez Labs
GitHub released actions/checkout v7 to mitigate "pwn requests," a supply-chain attack that exploits pull_request_target workflows to run forked code with base-repo privileges and steal secrets; v7 blocks fetching fork PR code in unsafe pull_request_target contexts by default, offers an explicit opt-out for reviewed use cases, and will be backported to older supported major versions on July 16, 2026. Maintainers are advised to audit workflows, upgrade or wait for backports, and only allow unsafe checkouts when explicitly reviewed and documented.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
