actions/checkout
AssessTools
A GitHub Actions action used to check out repository code into a workflow runner.
Why it's here
Placed in Assess: 1 article(s) of evidence from 2 source(s), led by security coverage, with 1 in the last 30 days. Confidence 32%.
Evidence (1)
- 8GitHub Blog·7/28/2026securityGitHub hardens npm and Actions against supply chain attacks
GitHub says it has rolled out several changes to disrupt common supply chain attack techniques targeting npm and GitHub Actions. The updates include temporary protection for high-impact npm accounts, safer defaults for actions/checkout, workflow trigger controls, and read-only cache access for untrusted Actions runs.