GitHub Security· Greg Ose·· 2026-07-29精选AI 评分72
GitHub 扰乱 npm 与 GitHub Actions 上的供应链攻击
Disrupting supply chain attacks on npm and GitHub Actions
AI 导读
GitHub 发布多项 npm 与 GitHub Actions 安全更新,通过账户只读保护、限制不受信任的触发器、只读缓存、staged publishing、默认禁用 install 脚本以及 Dependabot 冷却期等措施扰乱供应链攻击链,并新增自助凭据撤销与扩展凭据撤销 API 支持。
推荐理由
原文给出了 npm 与 GitHub Actions 的具体防护变化和开放入口,读者可以据此评估现有 CI/CD 工作流会受到哪些实际影响。
来源:GitHub Security · github.blog