A company I worked at went all in on GH too. The internal gh team probably going to do a fire drill this whole weekend and app teams forced to rotate all secrets and credentials.
Fortunately don’t have to deal with that shit anymore
Fortunately don’t have to deal with that shit anymore
Otherwise, if you continue to use it and it will run anytime there has been a push. Potentially on any branch, not just `main`! Depending on your GH config.
Unless you've blocked `tj-actions/changed-files` you're banking on the bad actor not coming back tonight and making malicious commit that exfils those secrets to pastebin.com.
You can whitelist
- all actions from a specific org (e.g. actions/*)
- a specific action (e.g. actions/setup-go)
- a specific version of a specific action (e.g. actions/setup-go@commit-sha)
Any workflow attempting to use actions outside of the whitelist will simply fail to start up.