Skip to content

Audit GitHub Actions workflow cache security #29

@wilsonianb

Description

@wilsonianb

https://adnanthekhan.com/2024/05/06/the-monsters-in-your-build-cache-github-actions-cache-poisoning

The takeaway is this:
Never run untrusted code within the context of the main branch if any other workflows use GitHub Actions caching.

https://github.com/codius/codius-workers/blob/main/.github/workflows/deploy-worker.yml

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions