

Prompt Injection in AI-Powered GitHub Actions
Security
10 min readSupply chain security, SLSA, OIDC, secrets management, policy as code, and hardening.


Prompt Injection in AI-Powered GitHub Actions


The PR Comment That Hijacked Three AI Agents


OWASP AI Agent Security Top 10: CI/CD Audit Guide

CI/CD Policy as Code: From YAML Security to Centralized Governance

When Your Security Scanner Gets Compromised


GitHub Actions Workflow Lockfiles Are Coming

GitHub Actions Artifact Attestations: SLSA Provenance and Supply Chain Defaults

GitHub Actions Permissions: Lock Down GITHUB_TOKEN


GitHub Actions OIDC Custom Properties: ABAC Cloud Access
GET TENKI