6 ms·
I made a scanner(ActionPin) for the workflow patterns this compromise exposed. ActionPin — a GitHub Actions hardening checker that flags unpinned third-party a
by zhenjing 5mo ago
I made a scanner(ActionPin) for the workflow patterns this compromise exposed.
ActionPin — a GitHub Actions hardening checker that flags unpinned third-party actions, overbroad workflow permissions, install scripts that touch secrets, and agent-triggered jobs that can reach production credentials.
ActionPin host on github.