|
|
|
|
|
by Liskni_si
269 days ago
|
|
If you can change a GitHub Actions workflow to exfiltrate a token, what prevents you from changing the workflow that uses Trusted Publishing to make changes to the package before publishing it? Perhaps by adding an innocent looking use of an external Action? |
|
However, exfiltrating a token is much more easy than modifying the workflow itself. A token is usually simply stored in an env variable.