Using GitHub Actions ? Be Aware of this High-Severity Injection Bug Found in GitHub Actions
Nov 23, 2020•9 min
Episode description
Felix Wilhelm of Google Project Zero found an injection Vulnerability affecting GitHub Actions and Workflow Commands specifically related to setting malicious environment variables by parsing STDOUT
Resources
https://github.blog/changelog/2020-10-01-github-actions-deprecating-set-env-and-add-path-commands/
For the best experience, listen in Metacast app for iOS or Android
