Web Hack List

Collected research

Characterizing the Security of GitHub CI Workflows

A study of GitHub Actions security against four properties: admittance control, execution control, code control and access to secrets. Across 447,238 workflows it finds 99.8 percent hold read-write repository tokens and 23.7 percent run repository code on pull_request, so an outsider who opens a pull request can execute arbitrary code with those privileges and reach secrets.

Record

Researcher
Igibek Koishybayev, Aleksandr Nahapetyan, Raima Zachariah, Siddharth Muralee, Bradley Reaves, Alexandros Kapravelos and Aravind Machiry
Published by
usenix.org
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Igibek Koishybayev, Aleksandr Nahapetyan, Raima Zachariah, Siddharth Muralee, Bradley Reaves, Alexandros Kapravelos and Aravind Machiry, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .