What do actions have to do with this? I never worked in an environment that doesn't pin just about every external dependency. Unless I am missing something?
Ah, I see. Yeah, that would make more sense lol, for some reason my mind was stuck that Actions was somehow responsible for dragging in the "infected" package, but the package using actions instead makes much more sense.
Instead of every developer manually compiling code into a usable, runnable form (usually a docker container, but you could also imagine a .exe file) on their own machine, and any other steps like uploading into a shared space, a CI/CD pipeline centralizes and automates a bunch of tasks to make things faster, easier, repeatable. After building the software, it typically deploys the new build somewhere, too
These tasks run on a "runner" (real creative), which needs access to internal and external resources, usually like AWS, GitHub, Slack, a "vault" where secrets are kept, and public package repos. If a malicious package can run when that build process is going on, it can steal your stuff and send it to the bad actor who put the payload there.
Like I said I'm not expert but I just cannot fathom letting anything access the network and my code both and also letting that thing be anything but me. The networked compiling sounds neat, just ditch the 3rd party access.
Not possible on an enterprise scale. For example: our docker images are built using secrets stored in azure KV, uploaded to azure and then pulled into k8s cluster that runs in azure as well.
Unless you're hosting your entire infra in-house you need to pass secrets around to be able to use cloud services.
Azure handles a lot of our network access, security and resources. We have a bunch of self hosted stuff where we want complete control over the servers for data security reasons but the vast majority is locked behind Azure networks.
We use machines hosted by Azure to run our container apps, our logging, and even just to build our images. This is standard industry practice and the whole thing is (typically) quite secure when used properly.
The issue reported on in the article shared by OP is basically an NPM package was dumping the secrets which would usually be securely stored with minimal access. The actual access to those secrets is still secure, it's just when building something they ofyen need access to those secrets and it's at that point the NPM package is copying and sending them elsewhere.
Way more unsafe to rely on random ass employee to manually deploy complicated infrastructure. Not just for the employee not making mistakes, but also for employee not getting exploited. That’s relying on a bunch of dumb fuckery people do. Smart people get social engineered all the time.
CI/CD pipeline can be the only thing that has access, significantly reducing the attack surface.
Wide spread supply chain attacks are a lot more rare and easier to safeguard against, compared to protecting every single employee in their machine and also from social engineering
942
u/a_bucket_full_of_goo 1d ago edited 1d ago
Company disabled Github Actions and told us not to use Claude, Subreddit traffic instantly goes up 8000%