Post #4047861
2026-07-23 22:30 UTC
RE: https://phpc.social/@packagist/116969590453454422
In the two month I'm doing security scans of PHP projects ( https://thephp.foundation/blog/2026/05/18/announcing-ecosystem-security-team/ ) I've come across multiple repositories with issues in their GitHub Actions. All fixed now.
The issues allowed attackers to ship a new releases with arbitrary, hostile code. No required interactions from the project authors.
Zizmor reported these issues. It also reports a lot of issues, read the story from the Packagist folks to learn about checking and hardening your GHA
More reading: https://phpunit.expert/articles/hardening-github-actions-workflows.html
Replies (0)
No replies.