Collected research
Characterizing the Security of GitHub CI Workflows
A study of GitHub Actions security against four properties: admittance control, execution control, code control and access to secrets. Across 447,238 workflows it finds 99.8 percent hold read-write repository tokens and 23.7 percent run repository code on pull_request, so an outsider who opens a pull request can execute arbitrary code with those privileges and reach secrets.
Record
- Researcher
- Igibek Koishybayev, Aleksandr Nahapetyan, Raima Zachariah, Siddharth Muralee, Bradley Reaves, Alexandros Kapravelos and Aravind Machiry
- Published by
- usenix.org
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Igibek Koishybayev, Aleksandr Nahapetyan, Raima Zachariah, Siddharth Muralee, Bradley Reaves, Alexandros Kapravelos and Aravind Machiry, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .