Trendora

pull_request_target

Assess

Techniques

A GitHub Actions workflow trigger that runs in the context of the target repository.

Why it's here

Placed in Assess: 1 article(s) of evidence from 2 source(s), led by security coverage, with 1 in the last 30 days. Confidence 32%.

Evidence (1)

  • 8GitHub Blog·7/28/2026security
    GitHub hardens npm and Actions against supply chain attacks

    GitHub says it has rolled out several changes to disrupt common supply chain attack techniques targeting npm and GitHub Actions. The updates include temporary protection for high-impact npm accounts, safer defaults for actions/checkout, workflow trigger controls, and read-only cache access for untrusted Actions runs.