# Imposter commits in GitHub Actions can bypass allowed workflow settings

DevFeed: [Imposter commits in GitHub Actions can bypass allowed workflow settings](<https://devfeed.tech/articles/what-the-fork-imposter-commits-in-github-actions-and-ci-cd-13319.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/what-the-fork-imposter-commits-in-github-actions-and-ci-cd>)

Published: 2023-03-08T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [GitOps](<https://devfeed.tech/topics/gitops.md>), [Git](<https://devfeed.tech/topics/git.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>)

Tags: [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [fork](<https://devfeed.tech/tags/fork.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [github-vulnerability](<https://devfeed.tech/tags/github-vulnerability.md>), [gitops](<https://devfeed.tech/tags/gitops.md>), [pull-request](<https://devfeed.tech/tags/pull-request.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [workflow](<https://devfeed.tech/tags/workflow.md>)

## AI overview

Chainguard reports a GitHub Actions vulnerability in which commits from forked repositories can bypass allowed workflow settings. The article explains how GitHub fork and commit-sharing behavior enables these imposter commits and why they pose a CI/CD supply-chain security risk.

## Source excerpt

Chainguard found a vulnerability in GitHub Actions that bypasses allowed Workflow settings by using commits from forked repositories. Read the report.