github-actions-goat icon indicating copy to clipboard operation
github-actions-goat copied to clipboard

GitHub Actions Goat: Deliberately Vulnerable GitHub Actions CI/CD Environment

Results 18 github-actions-goat issues
Sort by recently updated
recently updated
newest added
trafficstars

Organize the project into two parts 1. Simulation of past attacks - [ ] SolarWinds (SUNPOST) - already exists - [ ] Codecov (tampering of artifact in storage account) -...

- [ ] simulate exfiltration of token instead of repo (idea) - [ ] add block mode in harden-runner - [ ] add missing domain - storage.googleapis.com

https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#exfiltrating-data-from-a-runner

https://github.com/justinsteven/advisories/blob/master/2021_github_actions_checkspelling_token_leak_via_advice_symlink.md

incident

This pull request updates to the most recent release version 0.27.0 of the spellcheck GitHub action, I can see that you are using 0.17.0, so an update could be useful...