Skip to main content

One post tagged with "ci-cd"

View All Tags

Security Update: Hardening Pull Request Preview Workflows

Cloud Posse
Cloud Posse

We removed a pull_request_target-based preview workflow from our documentation repository after a responsible disclosure from security researcher Aviv Donenfeld. This was the last remaining instance of this pattern in our GitHub organization. The issue was limited to pull request preview environments for this repository, there is no indication it was ever exploited, and the overall impact was minimal.