US-Trustee-Program / Bankruptcy-Oversight-Support-Systems

Other
6 stars 1 forks source link

Make sure GitHub Action artifacts are not leaking our GitHub_Tokens or other secrets #847

Open governmentSponsored opened 2 months ago

governmentSponsored commented 2 months ago

This is in response to a blog article Tom Willis found: https://www.stepsecurity.io/blog/detect-leaked-secrets-in-github-action-workflow-artifacts

also this article: https://unit42.paloaltonetworks.com/github-repo-artifacts-leak-tokens/