Actions Supply Chain Security | GitHub
本章覆盖:third-party action;commit SHA pinning;compromised tag;permissions;secrets;self-hosted runner;untrusted PR;dependency update;CodeQL / scanning for workflow;Actions workflow 本身也是供应链入口。
本章知识点
- third-party action
- commit SHA pinning
- compromised tag
- permissions
- secrets
- self-hosted runner
- untrusted PR
- dependency update
- CodeQL / scanning for workflow
- Actions workflow 本身也是供应链入口