Semgrep events

Common Vulnerabilities in GitHub Actions - And How to Protect Against Them

June 4th, 2025
9:00 AM PT

GitHub Actions are quietly powering countless open-source and commercial projects—but they’re also an emerging target for attackers. From subtle pipeline misconfigurations to command injection exploits, threat actors are getting creative with how they compromise CI/CD systems. This webinar dives into the overlooked security risks of GitHub Actions and shows how to catch issues before they become backdoors.

Takeaways:

  • Spot common misconfigurations in GitHub Actions workflows before attackers do

  • Learn how command injection attacks work—and how to defend against them

  • Build safer pipelines with practical techniques for detection and mitigation

Vasilii Ermilov
Semgrep
Senior Security Researcher
Your privacy matters to us. By submitting this form, you agree to our Privacy Policy