Skip to content
Cloud Security DeskSearch
Menu

Evidence search

Search

Search titles, summaries, topics, providers, authors, and the full open-access corpus.

Results for “pull_request_target”

4 publications
Technical guideSource-based analysis

Stop pull_request_target workflows from running fork code

GitHub blocks pull_request_target in public repositories by default from November 2, 2026. Find the workflows that run fork code with secrets, split them, pin a checkout that refuses unsafe refs, and allow the rest deliberately.

Workload security · GitHub · By Cloud Security Desk
Technical guideSource-based analysis

Run AI coding agents in GitHub Actions without exposing secrets

Treat the agent job as an untrusted-input processor. Follow the outside text from the trigger that admits it to the credentials it can reach, then split reading from writing so a successful injection reaches nothing worth stealing.

AI systems · GitHub / Anthropic / Google / Microsoft · By Cloud Security Desk
Technical guideSource-based analysis

Pin third-party GitHub Actions and limit what they can reach

A tag can be moved under your workflow overnight. Pin every action to a commit SHA, enforce it across the organization, and cut the token and secret access a malicious action would inherit.

Workload security · GitHub / OpenSSF / CISA · By Cloud Security Desk
Technical guideSource-based analysis

Publish npm packages with trusted publishing instead of long-lived tokens

npm revoked classic tokens and capped write tokens at 90 days. Move CI releases to trusted publishing with staged approval, then protect the workflow, tags and environment that now hold publish authority.

Workload security · npm / GitHub / GitLab / CircleCI / Sigstore · By Cloud Security Desk