Skip to content

Comment on GitHub Actions is the weakest link

Comments

The OIDC federation between the runner and the cloud resources it touches , that credential gets created once. Permissive enough to not block the first deploy, and it is not what is reviewed when a pinning incident happens. Every one is looking at the action. The identity it runs as just sits there.

Common mistake is trusting the repo instead of the workflow. Then any workflow inherits the same cloud access.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.