If you use GitHub Actions to automate your CI/CD workflows, this post is for you.

CTO
João Brito

Attention developers, security teams, and DevSecOps professionals! This article summarizes the key points of a crucial video about the growing threat of supply chain attacks within the GitHub Actions ecosystem. Understand the real risks of these incidents.
What You Need to Know About Security in GitHub Actions:
Automation with GitHub Actions is essential in modern development, but it also opens up new attack surfaces. Three recent incidents, detailed in our video, expose critical vulnerabilities that can compromise the security of your projects:
CVE-2025-30066: Security Flaw in
tj-actions/changed-files: This real-world case demonstrates the dangers of using third-party actions without a complete security audit. Learn how this vulnerability was exploited and how to avoid similar scenarios.CVE-2025-30154: Vulnerability in
reviewdog/action-setup: Discover how an apparently secure action can become a gateway for exploitation. We analyze the potential impact and the lessons learned.CVE-2025-32955: Security Bypass in
harden-runnerby Sysdig: Even security tools can have flaws. Understand how a protection mechanism was bypassed, highlighting the need for a layered security approach.
Why Supply Chain Attacks in GitHub Actions Are a Real Threat?
These attacks are not theoretical. The consequences can be severe:
Secrets Leak: Exposure of API keys, tokens, and other sensitive information stored in your workflows.
Security Breaches: Introduction of malicious code into your development and production environments.
Loss of Trust: Compromise of the integrity of your automation processes, affecting the reliability of your deliveries.
Protect Your CI/CD Pipeline: Best Practices and Resources
The security of your software supply chain in GitHub Actions is not optional. It is essential to protect your digital assets and your users' trust.
Video Links:
Zero CVE Program: getup.io/images
Analysis of the
tj-actions/changed-filesAttack (Wiz Blog): https://www.wiz.io/blog/github-action-tj-actions-changed-files-supply-chain-attack-cve-2025-30066Analysis of the
reviewdog/action-setupAttack (Wiz Blog): https://www.wiz.io/blog/new-github-action-supply-chain-attack-reviewdog-action-setupAnalysis of the Bypass in
harden-runner(Sysdig Blog): https://sysdig.com/blog/security-mechanism-bypass-in-harden-runner-github-action/
Conclusion: Supply Chain Security Must Be a Priority
Do not ignore the risks. Prevention is key to avoiding supply chain attacks and protecting your environment.
#DevSecOps #GitHubActions #SupplyChainSecurity #SoftwareSecurity #CVE #CI/CD #SecureAutomation #SecureDevelopment #Cybersecurity
Newsletter Getup.
Atualizações sobre Kubernetes e Software Supply Chain Security todos os meses.
Operating Kubernetes in production for more than 13 years. With Quor, this experience extends to software supply chain security as well.
GET UP
© Getup · 2026

