pull_request_target
AssessTechniques
A GitHub Actions workflow trigger that runs in the context of the target repository.
Why it's here
Placed in Assess: 1 article(s) of evidence from 2 source(s), led by security coverage, with 1 in the last 30 days. Confidence 32%.
Evidence (1)
- 8GitHub Blog·7/28/2026securityGitHub hardens npm and Actions against supply chain attacks
GitHub says it has rolled out several changes to disrupt common supply chain attack techniques targeting npm and GitHub Actions. The updates include temporary protection for high-impact npm accounts, safer defaults for actions/checkout, workflow trigger controls, and read-only cache access for untrusted Actions runs.