# GitHub vulnerability

Published articles for GitHub vulnerability.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Open sourcing Octo STS

DevFeed: [Open sourcing Octo STS](<https://devfeed.tech/articles/open-sourcing-octo-sts-13197.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/open-sourcing-octo-sts>)

Published: 2024-05-02T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [octo sts](<https://devfeed.tech/topics/octo-sts.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Infrastructure as code](<https://devfeed.tech/topics/infrastructure-as-code.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [credential-leak](<https://devfeed.tech/tags/credential-leak.md>), [github](<https://devfeed.tech/tags/github.md>), [github-credentials](<https://devfeed.tech/tags/github-credentials.md>), [github-vulnerability](<https://devfeed.tech/tags/github-vulnerability.md>), [octo-sts](<https://devfeed.tech/tags/octo-sts.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [security-token-service](<https://devfeed.tech/tags/security-token-service.md>), [source](<https://devfeed.tech/tags/source.md>)

### AI overview

Chainguard announces the open sourcing of Octo STS, a GitHub Security Token Service designed to exchange short-lived third-party tokens for short-lived first-party tokens. The repository includes its source code and the infrastructure as code used to deploy and monitor it, enabling teams to inspect, host, and manage their own instance.

### Source excerpt

Open Source Octo STS Released -- Chainguard's solution to eliminate long-lived GitHub credentials. Improve security, collaborate, get updates.

## Continuous hardening of Chainguard's internal software supply chain

DevFeed: [Continuous hardening of Chainguard's internal software supply chain](<https://devfeed.tech/articles/continuous-hardening-of-chainguard-s-internal-software-supply-chain-13013.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/continuous-hardening-of-chainguards-internal-software-supply-chain>)

Published: 2024-02-21T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [Security](<https://devfeed.tech/topics/security.md>), [Docker Compose](<https://devfeed.tech/topics/docker-compose.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [github-vulnerability](<https://devfeed.tech/tags/github-vulnerability.md>), [hardending](<https://devfeed.tech/tags/hardending.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [least-privilege](<https://devfeed.tech/tags/least-privilege.md>), [minimalism](<https://devfeed.tech/tags/minimalism.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [terraform-provider](<https://devfeed.tech/tags/terraform-provider.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard describes how it mitigated a potentially vulnerable GitHub Actions workflow that could have affected the integrity of Docker images signed by its cosign Terraform Provider. The team responded within 24 hours and explains how least privilege, minimal defaults, and dependency minimization support software supply chain security.

### Source excerpt

See how Chainguard mitigated the potential vulnerable GitHub actions workflow "Pwn request" in less than 24 hours.

## Cybersecurity hygiene in co-working spaces: A practical guide

DevFeed: [Cybersecurity hygiene in co-working spaces: A practical guide](<https://devfeed.tech/articles/cybersecurity-hygiene-in-co-working-spaces-a-practical-guide-13018.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/cybersecurity-hygiene-in-co-working-spaces-a-practical-guide>)

Published: 2024-01-02T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Endpoint security](<https://devfeed.tech/topics/endpoint-security.md>), [network security](<https://devfeed.tech/topics/network-security.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [Git](<https://devfeed.tech/topics/git.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [USB](<https://devfeed.tech/topics/usb.md>)

Tags: [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [git](<https://devfeed.tech/tags/git.md>), [github-vulnerability](<https://devfeed.tech/tags/github-vulnerability.md>), [guide](<https://devfeed.tech/tags/guide.md>), [incident](<https://devfeed.tech/tags/incident.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-security](<https://devfeed.tech/tags/kubernetes-security.md>), [least-privilege](<https://devfeed.tech/tags/least-privilege.md>), [network-security](<https://devfeed.tech/tags/network-security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [usb](<https://devfeed.tech/tags/usb.md>)

### AI overview

A practical guide to cybersecurity hygiene in co-working spaces. It covers Kubernetes security, Git repository protection, device safety, layered defenses, incident response, and security awareness training.

### Source excerpt

Navigate the cybersecurity landscape in shared work environments with essential tips on device safety and incident response.

## Imposter commits in GitHub Actions can bypass allowed workflow settings

DevFeed: [Imposter commits in GitHub Actions can bypass allowed workflow settings](<https://devfeed.tech/articles/what-the-fork-imposter-commits-in-github-actions-and-ci-cd-13319.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/what-the-fork-imposter-commits-in-github-actions-and-ci-cd>)

Published: 2023-03-08T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [GitOps](<https://devfeed.tech/topics/gitops.md>), [Git](<https://devfeed.tech/topics/git.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>)

Tags: [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [fork](<https://devfeed.tech/tags/fork.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [github-vulnerability](<https://devfeed.tech/tags/github-vulnerability.md>), [gitops](<https://devfeed.tech/tags/gitops.md>), [pull-request](<https://devfeed.tech/tags/pull-request.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [workflow](<https://devfeed.tech/tags/workflow.md>)

### AI overview

Chainguard reports a GitHub Actions vulnerability in which commits from forked repositories can bypass allowed workflow settings. The article explains how GitHub fork and commit-sharing behavior enables these imposter commits and why they pose a CI/CD supply-chain security risk.

### Source excerpt

Chainguard found a vulnerability in GitHub Actions that bypasses allowed Workflow settings by using commits from forked repositories. Read the report.