GitHub Actions Checkout Now Blocks Risky pull_request_target Checkouts
ID: 84661139-9a14-59e2-820b-5ef4098593d4
STIX ID: report--84661139-9a14-59e2-820b-5ef4098593d4
Feed Name: Socket Blog
GitHub released actions/checkout v7 to block common unsafe patterns where privileged workflows (e.g., pull_request_target or certain workflow_run events) check out and execute attacker-controlled code from forked pull requests. The change prevents typical fork-ref checkouts by default and introduces an explicit allow-unsafe-pr-checkout opt-out; the report ties this update to prior high-impact supply-chain compromises (Nx, PostHog/Shai-Hulud, TanStack) and notes that the guardrail reduces but does not eliminate risks from other checkout mechanisms or workflow misconfigurations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
