GitHub Actions Checkout v7 blocks fork code by default, moves credentials to ephemeral storage
GitHub has released Checkout v7, a security-focused update to its most widely used GitHub Action, which powers millions of CI/CD workflows daily. The update blocks automatic checkout of fork pull request code when workflows run with elevated privileges, requiring developers to explicitly set a flag called 'allow-unsafe-pr-checkout: true' to override this behavior. Credentials, previously stored in .git/config where any containerized process could read them, are now written to an ephemeral file under the $RUNNER_TEMP directory that is deleted after each job and not accessible to container actions by default. The changes address a structural vulnerability where fork contributors could submit pull requests that execute malicious code with full access to repository secrets and tokens. The rewrite also migrated the codebase from CommonJS to ECMAScript Modules, patching known vulnerabilities in older dependencies, though Docker container actions now require Actions Runner v2.329.0 or later to function correctly.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in