Unfortunately that’s one of the downsides of publishing via CI. It’s a super interesting attack target and you can exploit it 24/7. https://bsky.app/profile/mattkeeter.com/post/3lcmagnpvlc2z
Reposted from
Matt Keeter
absolutely incredible attack vector
Comments
https://circleci.com/changelog/expression-based-context-restrictions/
Does GitHub Actions have an equivalent?