This product is not supported for your selected Datadog site. ().

Metadata

Id: 62ff6823-927a-427f-acf9-f1ea2932d616

Cloud Provider: github

Framework: CICD

Severity: High

Category: Insecure Configurations

Learn More

Description

GitHub Actions workflows can be triggered by a variety of events. Each trigger includes a GitHub context with details about the event, such as the user who triggered it, the branch name, and other relevant information. Some of this data, like the base repository name, changeset hash, or pull request number, is typically not controlled by the user and is unlikely to be used for injection.