Preview of State of GitHub Actions Security Report: Security of GH Workflows Building Blocks
ID: a1e6e8ea-e441-5a1a-b9f1-d04c73509f31
STIX ID: report--a1e6e8ea-e441-5a1a-b9f1-d04c73509f31
Feed Name: Security Boulevard
This report analyzes the security posture of GitHub Actions workflows across 2.5M files and finds systemic risks: dangerous triggers (e.g., pull_request_target, workflow_run) that can lead to RCE, widespread lack of dependency pinning (98.4%), default overly‑privileged workflow tokens, and unsafe use of self‑hosted runners. It provides concrete recommendations—avoid or gate risky triggers, minimize token permissions, pin action references, and restrict self‑hosted runners—to mitigate supply‑chain and execution‑context attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
