Report surfaces thousands of potential vulnerabilities in GitHub Workflows
The Insider News
1
Posts
1
Posters
0
Views
1
Watching
-
An analysis of 2.5 million GitHub Actions workflow files belonging to 553,000 organizations and personal users published today suggests many DevSecOps teams that use the GitHub continuous integration/continuous deliver (CI/CD) platform to build and deploy applications are relying on workflows that are often fundamentally insecure.
That's OK, the code managed by those GitHub Workflows have plenty of vulnerabilities as well