Evidence search
Search
Search titles, summaries, topics, providers, authors, and the full open-access corpus.
Results for “workflow execution protections”
2 publicationsTechnical guideSource-based analysisTechnical guideSource-based analysis
Stop pull_request_target workflows from running fork code
GitHub blocks pull_request_target in public repositories by default from November 2, 2026. Find the workflows that run fork code with secrets, split them, pin a checkout that refuses unsafe refs, and allow the rest deliberately.
Workload security · GitHub · By Cloud Security DeskRun AI coding agents in GitHub Actions without exposing secrets
Treat the agent job as an untrusted-input processor. Follow the outside text from the trigger that admits it to the credentials it can reach, then split reading from writing so a successful injection reaches nothing worth stealing.
AI systems · GitHub / Anthropic / Google / Microsoft · By Cloud Security Desk