Loading video player...
Securing Your GitHub Actions - Jaroslav Lobacevski, GitHub With recent supply chain compromises such as those impacting tj-actions and reviewdog (https://www.cisa.gov/news-events/alerts/2025/03/18/supply-chain-compromise-third-party-tj-actionschanged-files-cve-2025-30066-and-reviewdogaction) it is more important than ever to protect your GitHub Actions. This talk enumerates common GitHub Actions vulnerability patterns that the GitHub Security Lab team has seen in the wild and offers a set of best practices and tools to prevent them from occurring in your own CI/CD supply chain.