Skip to content
Topic

#Github Actions

20 articles on Github Actions — news, releases, guides and analysis from the SourceFeed engine.

npm's Frictionless Publish Era Is Over
Article 5d ago 0

npm's Frictionless Publish Era Is Over

GitHub's new npm and Actions defaults trade release speed for survivability — and the signing debate misses why.

Emeka Okafor
Another GitHub Actions Outage, and the Ninth in a Month

Another GitHub Actions Outage, and the Ninth in a Month

Article · 1w ago5
GitHub Actions Has Become GitHub's Single Point of Failure

GitHub Actions Has Become GitHub's Single Point of Failure

Article · 1w ago1
Sign and Verify Container Images with Cosign and Sigstore

Sign and Verify Container Images with Cosign and Sigstore

Tutorial · 1w ago0
Docker Hub Finally Does OIDC, but Only for Paying Orgs

Docker Hub Finally Does OIDC, but Only for Paying Orgs

Article · 1w ago0
Block Malicious npm Packages in CI with Socket.dev

Block Malicious npm Packages in CI with Socket.dev

Tutorial · 1w ago0
npm Breaks Its Oldest Promise to Kill the Worm

npm Breaks Its Oldest Promise to Kill the Worm

Article · 2w ago4
Block Secrets Before They Hit GitHub with Gitleaks

Block Secrets Before They Hit GitHub with Gitleaks

Tutorial · 2w ago0
Catch Jailbreaks in CI with garak, NVIDIA's LLM Red-Team Scanner

Catch Jailbreaks in CI with garak, NVIDIA's LLM Red-Team Scanner

Tutorial · 2w ago0
Automate Versioning and Changelogs with Changesets in a pnpm Monorepo

Automate Versioning and Changelogs with Changesets in a pnpm Monorepo

Tutorial · 1mo ago0
Build a Claude-Powered GitHub Actions PR Review Bot

Build a Claude-Powered GitHub Actions PR Review Bot

Tutorial · 1mo ago0
Miasma Proves Trusted Publishing Can Backfire Spectacularly

Miasma Proves Trusted Publishing Can Backfire Spectacularly

Article · 1mo ago0
The Cordyceps Exploits: Why Your CI/CD Pipelines Are Wide Open

The Cordyceps Exploits: Why Your CI/CD Pipelines Are Wide Open

Article · 1mo ago0
Audit Your Software Supply Chain: Generate an SBOM with Syft and Gate CI on a Grype Vulnerability Scan

Audit Your Software Supply Chain: Generate an SBOM with Syft and Gate CI on a Grype Vulnerability Scan

Tutorial · 1mo ago0
GitHub Hardens actions/checkout to Block Pwn Request Attacks

GitHub Hardens actions/checkout to Block Pwn Request Attacks

Article · 1mo ago0
Catch Risky Code Before It Merges: Add Semgrep SAST to Your GitHub Actions Pipeline

Catch Risky Code Before It Merges: Add Semgrep SAST to Your GitHub Actions Pipeline

Tutorial · 1mo ago0