CI/CD คือ production surface อีกจุดหนึ่ง
GitHub อธิบายว่าการโจมตี supply chain ช่วงล่าสุดมุ่งไปที่ package repository และ CI/CD เพื่อกระจายโค้ดอันตรายหรือขโมย credential ประเด็นนี้ย้ำว่า workflow ไม่ใช่แค่ไฟล์ประกอบการ deploy แต่เป็นส่วนหนึ่งของ production security boundary
มาตรการที่ประกาศครอบคลุมการ checkout จาก untrusted fork, สิทธิ์ของ cache token ในบาง context และ policy สำหรับควบคุมว่าใครหรือ event ใด trigger workflow ได้
สิ่งที่ควร review ใน repository ของเรา
เริ่มจากตรวจ pull_request_target, การใช้ action จาก third party, token permissions, cache key และ secret ที่ถูกส่งเข้าขั้นตอน build จากนั้น pin action และ dependency ที่มีผลกับ release ให้ตรวจสอบย้อนกลับได้
Dependabot cooldown ช่วยลดความเสี่ยงจากการรับ version update ทันที แต่ไม่ควรแทนที่การ review release note และ security update ที่ต้องรับอย่างเร่งด่วน
This article is an original summary and analysis. Facts are based on the linked primary source; performance figures remain vendor-reported where noted.