ended6월 12일· 1 sources

Unpinned Actions: Why 71% of GitHub Repositories Are at Risk

GitHub Actions의 71%, 공급망 공격에 노출되다

Why it matters

GitHub Actions have become a critical attack surface in 2025, with 71% of repositories leaving actions unpinned to mutable tags—a vulnerability exploited in recent supply-chain attacks like reviewdog and tj-actions/changed-files. The actionsec scanner identifies the top five GitHub Actions security footguns in milliseconds with zero dependencies, enabling developers to catch compromised workflows before malicious code executes with full repository privileges.

1
Sources
+0
24h
Growth
101d
Active
GitHub Actionssupply-chain attacksactionsecworkflow securityaction pinning

Sources

Related Issues