How Attackers Exploit pull_request_target: Secure Your GitHub CI/CD Workflows
GitHub Actions is powerful—but with great power comes… a long list of workflow security pitfalls. If you’ve spent any time around GitHub Actions, you’ve probably seen people casually using pull_request_target without fully understanding what it does. And honestly, that’s where most of the security issues begin. I’m Shreya Pohekar, and I work as a Security Researcher at Microsoft. Over the years of…