跳到正文
原文
GitHub Security· Greg Ose·· 2026-07-29精选AI 评分72

GitHub 扰乱 npm 与 GitHub Actions 上的供应链攻击

Disrupting supply chain attacks on npm and GitHub Actions

AI 导读

GitHub 发布多项 npm 与 GitHub Actions 安全更新,通过账户只读保护、限制不受信任的触发器、只读缓存、staged publishing、默认禁用 install 脚本以及 Dependabot 冷却期等措施扰乱供应链攻击链,并新增自助凭据撤销与扩展凭据撤销 API 支持。

推荐理由

原文给出了 npm 与 GitHub Actions 的具体防护变化和开放入口,读者可以据此评估现有 CI/CD 工作流会受到哪些实际影响。

来源:GitHub Security · github.blog