ended6월 12일· 1 sources
Unpinned Actions: Why 71% of GitHub Repositories Are at Risk
GitHub Actions의 71%, 공급망 공격에 노출되다
Why it matters
GitHub Actions have become a critical attack surface in 2025, with 71% of repositories leaving actions unpinned to mutable tags—a vulnerability exploited in recent supply-chain attacks like reviewdog and tj-actions/changed-files. The actionsec scanner identifies the top five GitHub Actions security footguns in milliseconds with zero dependencies, enabling developers to catch compromised workflows before malicious code executes with full repository privileges.
1
Sources
+0
24h
—
Growth
101d
Active
GitHub Actionssupply-chain attacksactionsecworkflow securityaction pinning