Actions Supply Chain Security | GitHub

本章覆盖:third-party action;commit SHA pinning;compromised tag;permissions;secrets;self-hosted runner;untrusted PR;dependency update;CodeQL / scanning for workflow;Actions workflow 本身也是供应链入口。

本章知识点

  • third-party action
  • commit SHA pinning
  • compromised tag
  • permissions
  • secrets
  • self-hosted runner
  • untrusted PR
  • dependency update
  • CodeQL / scanning for workflow
  • Actions workflow 本身也是供应链入口