信頼されていないトリガーに対する読み取り専用の Actions キャッシュRead-only Actions cache for untrusted triggers
この記事は参考になりましたか?Was this article useful?
匿名の公開いいねです。記事の保存・お気に入りではなく、Featured、Top 3、重要度、掲載順位には影響しません。仕組みとプライバシーAnonymous public likes are reactions, not saved articles or bookmarks. They do not affect Featured, Top 3, importance, or listing order.How it works and privacy
AI2 点サマリSummary highlight
- フォークからのPRなど信頼できないトリガーに対し、Actionsキャッシュへのアクセスを読み取り専用に制限する機能が追加された。
- これによりキャッシュポイズニング攻撃を防ぎ、サプライチェーンセキュリティが強化される。
GitHub Actions now restricts cache access to read-only for untrusted triggers like fork pull requests, preventing cache poisoning attacks and strengthening supply chain security.
本ページの要約は AI による自動生成です。日本語版と英語版は言語ごとに独立して生成されるため、表現や詳しさが異なる場合があります。正確性は元記事 (github.blog) をご確認ください。The summaries are AI-generated independently for each language, so wording and detail may differ. Verify accuracy at the original source (github.blog).





