logo

Preview of State of GitHub Actions Security Report: Security of GH Workflows Building Blocks

ID: a1e6e8ea-e441-5a1a-b9f1-d04c73509f31

STIX ID: report--a1e6e8ea-e441-5a1a-b9f1-d04c73509f31

Feed Name: Security Boulevard

Threat Score
60/100

Date Published: 2024-08-09

Date Updated: 2026-04-22

Author: Noam Dotan

...
...

This report analyzes the security posture of GitHub Actions workflows across 2.5M files and finds systemic risks: dangerous triggers (e.g., pull_request_target, workflow_run) that can lead to RCE, widespread lack of dependency pinning (98.4%), default overly‑privileged workflow tokens, and unsafe use of self‑hosted runners. It provides concrete recommendations—avoid or gate risky triggers, minimize token permissions, pin action references, and restrict self‑hosted runners—to mitigate supply‑chain and execution‑context attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.