Skip to content

Comment on GitHub Actions is the weakest link

Comments

pull_request_target is criminally negligent -- github should simply disable it.

The security risk for running unvalidated code on any random PR with access to account secrets has no legitimate use case which outweighs its unbounded risk.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.