Hello @hugo-syn 👋
I recently came across https://openssf.org/blog/2024/08/12/mitigating-attack-vectors-in-github-workflows/
From a defensive aspect, it would be awesome to be able to detect impostor commit used in github actions using octoscan.
But this is more an indicator of compromise rather than a vulnerability. What do you think about adding this kind of rule?
Hello @hugo-syn 👋
I recently came across https://openssf.org/blog/2024/08/12/mitigating-attack-vectors-in-github-workflows/
From a defensive aspect, it would be awesome to be able to detect impostor commit used in github actions using octoscan.
But this is more an indicator of compromise rather than a vulnerability. What do you think about adding this kind of rule?