Remove tags workflow
article thumbnail

The GitHub Actions Worm: Compromising GitHub Repositories Through the Actions Dependency Tree

Prisma Clud

Get an in-depth look at the attack vectors, technical details and a real-world demo in this blog post highlighting our latest research. When a GitHub Actions workflow uses an action, it downloads a zip of the repository via the GitHub API, bypassing the clone count. Additionally, actions can depend on actions in one of two ways.

Malware 144
article thumbnail

Unpinnable Actions: How Malicious Code Can Sneak into Your GitHub Actions Workflows

Prisma Clud

It turns out, though, that action pinning comes with a downside — a pitfall we call "unpinnable actions" that allows attackers to execute code in GitHub Actions workflows. Action Pinning GitHub Actions offers a powerful way to automate your software development workflow, including running tests, linting code, deploying applications and more.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Trending Sources

article thumbnail

GitHub Actions: running them securely

Xebia

By creating a workflow file you run actions on code updates to build your application, automate triaging tasks from issues, and loads of other helpful uses. To understand why, you need to know what the attack vectors of your workflow are and how you can guard yourself against them. Unfortunately, this is highly insecure!

article thumbnail

Continuous deployment for Artifact Registry container images

Xebia

Therefore, this blog shows how to configure a continuous deployment pipeline for container images. These notifications include the action (insert/delete) and the digest / tag of the container image. To govern the process, the process could be implemented using Cloud Workflows. Target implementation. Cloud Build triggers.

Cloud 130
article thumbnail

Continuous deployment for Artifact Registry container images

Xebia

Therefore, this blog shows how to configure a continuous deployment pipeline for container images. These notifications include the action (insert/delete) and the digest / tag of the container image. To govern the process, the process could be implemented using Cloud Workflows.

Cloud 130
article thumbnail

Our Latest Open Source Innovation, Yor: Automated IaC Tag and Trace

Palo Alto Networks

To make that process easier to navigate, many organizations leverage cloud tagging as a scalable way to attribute cloud resources to organizational owners. Tags can simplify operational tasks, cost allocation, access control, automation and risk management. Introducing Yor for Automatic IaC Tagging.

article thumbnail

Simplifying Data Management with Amazon S3 Lifecycle Configuration

Perficient

In this blog post, we will explore the steps involved in setting up S3 Lifecycle Configuration, enabling you to streamline your data management workflow and save costs in the long run. You can choose to apply the rule to all objects in the bucket or define specific prefixes, tags, or object tags to narrow down the scope.

Storage 59