GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns
ID: 956426f9-fe70-55f0-bc47-fde2e9e13b38
STIX ID: report--956426f9-fe70-55f0-bc47-fde2e9e13b38
Feed Name: The Hacker News
GitHub has changed the official actions/checkout action to refuse common 'pwn request' patterns by default for pull_request_target and relevant workflow_run events, preventing untrusted fork pull-request checkouts that could execute attacker-controlled code with the base repository's GITHUB_TOKEN and secrets. The update — backported to supported versions — aims to reduce software supply-chain attacks that have previously led to compromises (e.g., s1ngularity, PostHog, TanStack), while GitHub advises restricting pull_request_target usage, limiting workflow permissions, and avoiding executing untrusted code.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
