jeremylong / musical-octo-carnival

A journey through the insecure defaults in GitHub Actions - wait who committed code to my repo?
Apache License 2.0
3 stars 1 forks source link

Act1: Introduce Malicious Code #1

Closed jeremylong closed 2 years ago

jeremylong commented 2 years ago

When the action runs - the build will pass. The warning.md file will not be created until the merge occurs and the code executes against main.

Note, this abuse is in plain site. The malicious code could be hidden in a new or upgraded dependency.