GitHub Actions hardens checkout security to block ‘pwn request’ attacks

New Products

Summary

GitHub is hardening actions/checkout v7 to block risky pull_request_target and workflow_run usage that can expose repositories to pwn request attacks. The new default fails workflows that try to fetch unreviewed fork code unless developers explicitly opt out with allow-unsafe-pr-checkout. GitHub will backport the change to all supported major versions on July 16, so many workflows using floating major tags will inherit the protection automatically. Teams pinning to specific versions will need to upgrade through their normal dependency update process, such as Dependabot. The move signals a broader shift toward secure-by-default behavior across GitHub Actions.

Classifications

industries
Fintech & Banking
applications
Data Management

AskAI Classifications

Labels
No AI classifications detected

Linked Companies

Semmle
$1M to $5M