Hopefully GH will apply this to Github Actions, which seem like an exploit vector just sitting there.
GH Actions are:
- complex enough to develop that third-party solutions are attractive, especially for simple-seeming tasks (I have just been through this)
- but yay there's a "marketplace" for actions!
- the code in the marketplace is the wild-west, but you'll find something that seems like it'll do what you want
- you'd better hope the code that was committed to be executed is actually the compiled source code (if, eg, it's based on the official Typescript example and committing some [com/trans]piled JS blob that is what actually gets executed)
- it has access to your code, maybe including write access
- or it could do damn near anything else