By targeting the automated workflows around repositories with targeted pull requests, attackers can potentially target ...
GitHub’s actions/checkout v7 now blocks risky fork PR checkouts in privileged workflows to reduce common pwn request attacks.