Primer on GitHub Actions Security - Threat Model, Attacks and Defenses (Part 1/2)
ID: 72edeb0f-668b-5170-986f-fc6a8ea96e67
STIX ID: report--72edeb0f-668b-5170-986f-fc6a8ea96e67
Feed Name: Wiz Blog
Threat Score
**Executive summary:** This report analyzes GitHub Actions threat models and documents three major classes of incidents—pull_request_target misconfigurations enabling PR-based code execution, script/expression injection from unsanitized inputs, and compromised third-party actions—illustrating real supply-chain compromises (Trivy, Ultralytics, tj-actions) that led to secret exfiltration and widespread malware distribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
