Comment by zhenjing

6 months ago

I made a scanner(ActionPin) for the workflow patterns this compromise exposed.

ActionPin — a GitHub Actions hardening checker that flags unpinned third-party actions, overbroad workflow permissions, install scripts that touch secrets, and agent-triggered jobs that can reach production credentials. ActionPin host on github.