Home / Companies / GitHub / Blog / Post Details
Content Deep Dive

Securing the open source supply chain across GitHub

Blog post from GitHub

Post Details
Company
Date Published
Author
Zachary Steindler
Word Count
735
Company Posts That Month
22
Language
English
Hacker News Points
-
Post removed?
No
Summary

Over the past year, there has been an increase in attacks on the open-source supply chain, particularly targeting secrets like API keys to publish malicious packages and propagate attacks across more projects. These attacks frequently begin by exploiting workflows on GitHub Actions. To combat this, GitHub recommends enabling CodeQL for security best practices, avoiding triggering workflows on pull_request_target, and pinning third-party Actions to full-length commit SHAs. In collaboration with OpenSSF, GitHub has implemented "trusted publishing" to remove secrets from build pipelines and improve package security across various repositories like npm, PyPI, and RubyGems. As part of ongoing efforts to enhance security, GitHub has accelerated the rollout of new capabilities in response to significant attacks such as Shai-Hulud, focusing on malware detection and community engagement to address potential backward incompatibilities. GitHub remains committed to strengthening open-source security and encourages community feedback as it advances its security roadmap for GitHub Actions and npm.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 4 1,821 338 111 +22%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.