GitHub Actions Security: The CI/CD Attack Surface You're Probably Not Auditing
Most teams treat their .github/workflows directory as plumbing. It gets written once, copied between repos, and forgotten. But that YAML is executable code with access to your repository, your secrets
jaytank.hashnode.dev9 min read