Hackernews posts about GitHub Actions
- GitHub Actions is the weakest link (nesbitt.io)
- Why I built wrkflw to validate and run GitHub Actions locally (blog.gokuls.in)
- We hardened zizmor's GitHub Actions static analyzer (blog.trailofbits.com)
- Scheduled GitHub Actions are now useless (www.viblo.se)
- Actions-cool/issues-helper GitHub Action Compromised (github.com)
- Keeping your GitHub Actions and workflows secure: Preventing pwn requests (2021) (securitylab.github.com)
- GitHub Actions and Consequences (tylercipriani.com)
- Actions-cool/issues-helper GitHub Action Compromised (www.stepsecurity.io)
- LogLeak: Composer GitHub Actions token disclosure in error messages, patched (blog.packagist.com)
- What GitHub Actions Would Look Like If Designed Today (almostintuitive.com)
- Re-Imagining GitHub/GitLab Actions (almostintuitive.com)
- A free solution to the GitHub Actions supply chain crisis (developerwithacat.com)
- Static Analysis for GitHub Actions (github.com)
- Static Analysis for GitHub Actions (github.com)
- GitHub Action Runner Alternatives (binhong.me)
- A free solution to the GitHub Actions supply chain crisis (developerwithacat.com)
- Show HN: Cosmo – Desktop agent with generated UI (www.buildcosmo.com)
- Show HN: A timeline of recent open source CVE intensity and volume (supplychain.fail)
- Show HN: Open-source tool to explore malware clusters and shared infrastructure (malwaresiblings.up.railway.app)