GitHub Actions Security: The CI/CD Attack Surface You're Probably Not Auditing
A practical field guide to GitHub Actions vulnerabilities - script injection, privileged triggers, permissions/OIDC, supply chain - and how offline static analysis with actionward catches them before merge.
Sep 8, 20269 min read
