安全攻防
evening
GitHub 更新 actions/checkout 以阻止常见的 Pwn 请求攻击模式
摘要
GitHub is moving to strengthen software supply chain security by updating "actions/checkout" to block pwn request attacks that exploit the risky use of the "pull_request_target workflow" trigger to ru
the
GitHub
actions
checkout
request
2026-06-23
1 阅读
约1分钟阅读
info@thehackernews.com (The Hacker News)
字号:
GitHub 正在通过更新“actions/checkout”来阻止 pwn 请求攻击,从而加强软件供应链安全性,这些攻击利用“pull_request_target 工作流”触发器的危险使用,以工作流的完全权限运行恶意代码。最新版本的“actions/checkout”于 2026 年 6 月 18 日生效,这是用于将存储库检出到 GitHub 的官方 GitHub 操作
这篇文章对您有帮助吗?
订阅66必读
每日精选科技资讯,直达你的邮箱