GitHub Actions Supply Chain Attacks: How to Actually Harden Your CI/CD Pipeline
Your team has pinned every third-party action to an immutable SHA. Runners are GitHub-hosted, ephemeral, isolated. Someone ran zizmor once and filed a ticket. The posture feels done.
