Skip to content

project

GitHub Actions

GitHub's built-in CI/CD platform that runs automated build, test, and deployment workflows defined in .github/workflows files.

Known aliases

  • Actions
  • Actions cache
  • actions/checkout
  • Actions runners
  • actions/setup-python
  • Actions workflows
  • aws-actions/amazon-ecs-deploy-express-service
  • GHA
  • GitHub
  • GitHub Action
  • GitHub Actions runners
  • GitHub Actions workflows
  • GitHub Action workflows
  • GitHub hosted runners
  • GitHub Marketplace
  • GitHub Secrets
  • GitHub workflow
  • .github/workflows
  • macOS runners
  • setup-uv
  • ubuntu-latest runner

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

A static denylist stopped one more prompt injection than no protection in a coding-agent study

Bouras, Dai and Mechtaev found a static denylist let 46 of 75 prompt injections execute in a coding agent, against 3 under preflight-scoped capabilities. A same-day Google report of malware stealing OIDC tokens from GitHub Actions runners puts the outer limit on an agent in the CI job's permissions.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence50
security3 publishers

Two actions-cool GitHub Actions resumed running the Mini Shai-Hulud stealer after coming back online

Two actions-cool GitHub Actions hijacked on May 18 came back online on September 16, still serving the Mini Shai-Hulud stealer to tag-pinned workflows. Only workflows pinned to a pre-May 18 commit SHA escaped; the rest have CI secrets to rotate.

Perspective Coverage

3 publishers
Builder
Builder 43%
Operator
Operator 47%
Investor
Investor 10%

Reality

Evidence60
Adoption40
Hype gap+15
Incentives30
Confidence65
build1 publisher

Tag-pinned workflows re-ran Mini Shai-Hulud after issues-helper was re-enabled

Socket says workflows using issues-helper@v2.2.1 re-ran Mini Shai-Hulud after the Action was re-enabled on September 16 with its malicious tags intact. The earlier takedown only made those jobs fail, so the fix that holds is dropping the Action or pinning a verified commit SHA.

Publishers:dev.to

Reality

Evidence55
Adoption35
Hype gap+10
Incentives
Insufficient
Confidence55
security4 publishers

A Copilot Autofix Wrote the Bug, and an Autonomous Agent Cashed It for Snowflake's Jira

Wiz says its Red Agent found and exploited a GitHub Actions injection that an AI "autofix" commit introduced five days earlier, reaching Snowflake's internal Jira with no human in the loop.

Perspective Coverage

4 publishers
Builder
Builder 43%
Operator
Operator 42%
Investor
Investor 15%

Reality

Evidence58
Adoption
Insufficient
Hype gap+35
Incentives70
Confidence62
product4 publishers

Cursor becomes a code host by default, and GitHub's seven outages in 15 days is the opening

Origin arrives opt-out on every paid Cursor plan with no published terms on retention, residency or training use. GitHub's reliability record is what makes the pitch land.

Perspective Coverage

4 publishers
Builder
Builder 39%
Operator
Operator 34%
Investor
Investor 27%

Reality

Evidence72
Adoption
Insufficient
Hype gap+30
Incentives60
Confidence65
build3 publishers

GitHub's autoscaler watched the wrong meter, and auth, CI and Copilot fell together

The August 17 postmortem describes a sidecar that hit its concurrency limit while its autoscaler measured the host, then a VS Code retry bug that kept Copilot down hours after everything else returned.

Perspective Coverage

3 publishers
Builder
Builder 39%
Operator
Operator 38%
Investor
Investor 23%

Reality

Evidence66
Adoption82
Hype gap−12
Incentives58
Confidence64
security7 publishers

Attacker copied 170 CrowdSec repositories with a departed employee's still-live GitHub token

CrowdSec kept a leaver's GitHub access open so he could finish some work, his laptop was hit by the TanStack npm compromise on May 11, and the repositories were copied on May 22 and posted to a forum on September 16.

Publishers:crowdsec.netgithub.cominfosecurity-magazine.comold.tanstack.comorca.securitysecurityweek.comthehackernews.com

Perspective Coverage

7 publishers
Builder
Builder 39%
Operator
Operator 52%
Investor
Investor 9%

Reality

Evidence55
Adoption
Insufficient
Hype gap+15
Incentives65
Confidence60

Earlier coverage

  1. Claude Haiku overtook ElevenLabs as the most variable stage in Loquent's phone pipeline

    Build · September 24, 2026 · 1 publisher

  2. GitHub will meter every Copilot plan by token consumption from June 1

    Science · September 23, 2026 · 2 publishers

  3. A DPRK-linked package campaign has started publishing to HashiCorp's Terraform Registry

    Security · September 23, 2026 · 1 publisher

  4. 1,039 opted-in GitHub users rate their own code a small lever on emissions

    Build · September 23, 2026 · 1 publisher

  5. An agent now picks the packages the person prompting it will never see

    Build · September 23, 2026 · 1 publisher

  6. Verifying one merged GitHub Actions env: fix took seven hops across four files

    Build · September 22, 2026 · 1 publisher

  7. An Android release pipeline consumed several times GitHub's 500MB Actions quota in about ten days

    Build · September 22, 2026 · 1 publisher

  8. npm keeps accepting write tokens after you switch on OIDC trusted publishing

    Product · September 22, 2026 · 1 publisher

  9. CircleCI's open preview runs GitHub Actions YAML on its own control plane

    Build · September 22, 2026 · 1 publisher

  10. GitHub will restrict pull_request_target by default on affected public repos on November 2, 2026

    Product · September 21, 2026 · 1 publisher

  11. A kprobe on tcp_connect killed an npm postinstall's curl inside AWS CodeBuild

    Build · September 21, 2026 · 1 publisher

  12. GitHub's cleanup job watched replica lag while the primary ran out of connections

    Build · September 20, 2026 · 1 publisher

  13. GitHub Actions deploys into a private EC2 instance through the SSM agent's outbound connection

    Build · September 20, 2026 · 1 publisher

  14. Blacksmith enforces its org-only rule by leaving the job queued forever

    Build · September 20, 2026 · 1 publisher

  15. A Claude routine wrote a README into a pull request from Anthropic's own infrastructure

    Build · September 20, 2026 · 1 publisher

  16. The 2 a.m. operator test moved every slow call out of this billing app's request path

    Build · September 19, 2026 · 1 publisher

  17. A skills.lock file puts Agent Skills behind the same digest check as an npm dependency

    Build · September 19, 2026 · 1 publisher

  18. Sourcegraph's fleet migration agent repairs failing CI only after you hand it a log-reading token

    Build · September 19, 2026 · 1 publisher

  19. OCI's Workload Identity Federation exchanges a GitHub OIDC token for a short-lived session

    Build · September 18, 2026 · 1 publisher

  20. A self-hosted LLM tool's real RAM floor shows up in closed issues and the workflow YAML

    Build · September 18, 2026 · 1 publisher

  21. The scope you grant at install decides whether an AI reviewer can block a merge

    Build · September 18, 2026 · 1 publisher

  22. A predictable pnpm cache key carried fork code into TanStack's npm release workflow

    Build · September 18, 2026 · 1 publisher

  23. uv 0.12 flipped the uv init flag one cheatsheet had long recommended

    Build · September 18, 2026 · 1 publisher

  24. Junie /demo builds the app and drives the UI so the reviewer watches instead of clicking

    Build · September 18, 2026 · 1 publisher

  25. The App Runner exit starts with two IAM roles you write yourself

    Build · September 18, 2026 · 1 publisher

  26. Elastic Beanstalk's Cluster Mode shares one EKS cluster across every app in a subnet set

    Build · September 17, 2026 · 1 publisher

  27. A backdoored TanStack dependency lifted the CI key that could read CrowdSec's private repositories

    Build · September 17, 2026 · 1 publisher

  28. Play's "no countries" error described the empty alpha track the pipeline was aimed at

    Build · September 17, 2026 · 1 publisher

  29. One --exclude-table-data flag shrinks this nightly Postgres backup; a separate R2 lifecycle rule keeps it a year

    Build · September 17, 2026 · 1 publisher

  30. A workflow_run listener reads the shutdown-signal line before it retries a dead CI job

    Build · September 16, 2026 · 1 publisher

  31. Sample coverage config lets one of the four CI gates pass without new coverage

    Build · September 16, 2026 · 1 publisher

  32. A workflow GitHub synthesises for Dependabot crashed a cron watchdog three nights running

    Build · September 15, 2026 · 1 publisher

  33. Two steps consume 187 of the 198 seconds in Playwright's default CI run

    Build · September 15, 2026 · 1 publisher

  34. Resolving 31 action pins caught dependency-review-action's v3 tag two majors behind

    Build · September 14, 2026 · 1 publisher

  35. The drift job that catches a console fix needs write access to the state lock

    Build · September 14, 2026 · 1 publisher

  36. A single rule produced 59 of 61 medium findings before its author read GitHub's docs

    Build · September 13, 2026 · 1 publisher

  37. A redundant dynamic import crashed every route at module load in the merged bundle

    Build · September 13, 2026 · 1 publisher

  38. A sha256 sidecar now decides what the posting agent is allowed to attach

    Build · September 13, 2026 · 1 publisher

  39. A workflow_run chain keeps the fork's code out of the job that holds the secrets

    Build · September 13, 2026 · 1 publisher

  40. Signed payload's subject binds soit's image to a digest, not directly to its v1.0.0 tag

    Build · September 13, 2026 · 1 publisher