Skip to main content
All articles

Your pipeline has more access than any engineer on your team

A 60-second check of your GitHub Actions workflows for the patterns CI supply-chain attacks rely on: pull_request_target, movable tags, long-lived keys and default token permissions.

Sahil BansalConnect

2 min readFrom LinkedIn

5,561 repos backdoored in 6 hours.

No zero-day. No leaked password. Just GitHub Actions workflows that trusted too much.

That was the Megalodon campaign in May. Before it came tj-actions, Trivy, Checkmarx and Bitwarden CLI. The playbook was the same each time: get into CI, steal the secrets, walk into prod.

The uncomfortable part: your pipeline probably has more access than any engineer on your team. AWS keys, registry tokens, deploy rights. Almost nobody reviews it like prod.

Run this 60-second check on your repo

1. Workflows triggered by pull_request_target

grep -rn "pull_request_target" .github/workflows

Any hit → make sure it never runs PR code with secrets in scope.

2. Actions pinned to a tag

grep -rnE "uses: .+@v[0-9]" .github/workflows

Any hit → you're trusting a tag someone can move. Pin to a commit SHA.

3. Long-lived cloud keys

grep -rn "AWS_SECRET_ACCESS_KEY" .github/workflows

Any hit → long-lived keys waiting to be stolen. Switch to OIDC.

4. Default token permissions

grep -L "permissions:" .github/workflows/*.yml

Any file listed → default token permissions. Set them explicitly, read-only first.

All four clean? You're ahead of most teams. Not clean? You just found this sprint's most important ticket.

How many hits did you get?

Originally shared on LinkedIn.

  • GitHub Actions
  • Supply chain security
  • CI/CD

Written by Sahil Bansal

DevOps and platform engineer. I write about the infrastructure decisions I have had to live with.

Connect