GitHub will now send a Dependabot alert for vulnerable GitHub Actions which could make it easier to stay up to date and fix security vulnerabilities in your actions workflows.
GitHub Actions (opens in new tab) is the platform’s continuous integration and delivery (CI/CD) solution, which allows users to automate their software development pipeline.
The new alerts will be powered by the GitHub Advisory Database, which is a security vulnerability database inclusive of Common Vulnerabilities and Exposures (CVEs) and GitHub-originated security advisories taken from the world of open source software.
How can I enable the feature?
To receive alerts on GitHub Actions and vulnerabilities impacting your code, you can enable Dependabot by selecting “Enable all” under the Code security and analysis tab.
If you already happen to be using Dependabot, no problem, there is no additional action required.
You can also contribute some of your wisdom to help other users become more secure.
If you are the owner of a GitHub Action and you discover a vulnerability, you can start the process of creating an advisory from the security tab in your repository.
Once the repository advisory is created and tagged within the GitHub Action ecosystem, the GitHub curation team will review the repository advisory and create a global advisory when appropriate.
You can find out more about managing vulnerable dependencies on GitHub by heading here (opens in new tab).
Github isn’t the only company that is looking to remedy some of the vulnerabilities related to open source code, which is a common way for cybercriminals to try and hijack endpoints.
It’s a topic that gaining the attention of the wider technology industry, which is understandable as open source vulnerabilities have been the causes of some of the most devasting cyber attacks of the past few years, including the Log4j attack.
Google recently said (opens in new tab) it “will continue to make open source security a priority and urge others to do the same because the health and availability of open source projects strengthen the security posture of users and developers everywhere.”
- Want to beef up your organization’s security? Chckout our guide to the best firewalls