JFrog's AI-powered security research bot, RepoHunter, proactively identified 13 critical CI/CD vulnerabilities across major open-source projects including Ansible, QGIS, Telepresence, and TC39 JavaScript proposals. The vulnerabilities stem from 'Pwn Request' patterns where GitHub Actions workflows using pull_request_target
•15m read time• From jfrog.com
Table of contents
Why CI/CD is the New TargetWhat Is a “Pwn Request” / GitHub Actions CI Takeover?RepoHunter: Hunting CI Takeovers Before They ScaleFour Phases of a CI Supply Chain AttackRepoHunter CI\CD Takeover SummaryHypothetical Example: A Shai-Hulud-Style CI WormVulnerability Deep Dive: Ansible PlatformConclusion – Securing CI as Critical InfrastructureSort: