Unpacking Security Scanners for GitHub Actions Workflows
Fuente:
arXiv
Guardado en:
| Autores principales: | Fares, Madjda, Gamage, Yogya, Baudry, Benoit |
|---|---|
| Formato: | Preprint |
| Publicado: |
2026
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
Ejemplares similares
On the effectiveness of Large Language Models for GitHub Workflows
por: Zhang, Xinyu, et al.
Publicado: (2024)
por: Zhang, Xinyu, et al.
Publicado: (2024)
Heimdallr: Characterizing and Detecting LLM-Induced Security Risks in GitHub CI Workflows
por: Ruan, Bonan, et al.
Publicado: (2026)
por: Ruan, Bonan, et al.
Publicado: (2026)
Maven-Lockfile: High Integrity Rebuild of Past Java Releases
por: Schmid, Larissa, et al.
Publicado: (2025)
por: Schmid, Larissa, et al.
Publicado: (2025)
Characterizing and Modeling the GitHub Security Advisories Review Pipeline
por: Segal, Claudio, et al.
Publicado: (2026)
por: Segal, Claudio, et al.
Publicado: (2026)
Can Highlighting Help GitHub Maintainers Track Security Fixes?
por: Liu, Xueqing, et al.
Publicado: (2024)
por: Liu, Xueqing, et al.
Publicado: (2024)
Security Weaknesses of Copilot-Generated Code in GitHub Projects: An Empirical Study
por: Fu, Yujia, et al.
Publicado: (2023)
por: Fu, Yujia, et al.
Publicado: (2023)
Security in the Age of AI Teammates: An Empirical Study of Agentic Pull Requests on GitHub
por: Siddiq, Mohammed Latif, et al.
Publicado: (2026)
por: Siddiq, Mohammed Latif, et al.
Publicado: (2026)
Is GitHub's Copilot as Bad as Humans at Introducing Vulnerabilities in Code?
por: Asare, Owura, et al.
Publicado: (2022)
por: Asare, Owura, et al.
Publicado: (2022)
Exploring User Privacy Awareness on GitHub: An Empirical Study
por: Alfieri, Costanza, et al.
Publicado: (2024)
por: Alfieri, Costanza, et al.
Publicado: (2024)
LLM-Enabled Open-Source Systems in the Wild: An Empirical Study of Vulnerabilities in GitHub Security Advisories
por: Shifat, Fariha Tanjim, et al.
Publicado: (2026)
por: Shifat, Fariha Tanjim, et al.
Publicado: (2026)
Unveiling A Hidden Risk: Exposing Educational but Malicious Repositories in GitHub
por: Masud, Md Rayhanul, et al.
Publicado: (2024)
por: Masud, Md Rayhanul, et al.
Publicado: (2024)
On the Prevalence and Usage of Commit Signing on GitHub: A Longitudinal and Cross-Domain Study
por: Sharma, Anupam, et al.
Publicado: (2025)
por: Sharma, Anupam, et al.
Publicado: (2025)
Bugdar: AI-Augmented Secure Code Review for GitHub Pull Requests
por: Naulty, John, et al.
Publicado: (2025)
por: Naulty, John, et al.
Publicado: (2025)
IssueGuard: Real-Time Secret Leak Prevention Tool for GitHub Issue Reports
por: Rahman, Md Nafiu, et al.
Publicado: (2026)
por: Rahman, Md Nafiu, et al.
Publicado: (2026)
Six Million (Suspected) Fake Stars in GitHub: A Growing Spiral of Popularity Contests, Spams, and Malware
por: He, Hao, et al.
Publicado: (2024)
por: He, Hao, et al.
Publicado: (2024)
Security Concerns in Generative AI Coding Assistants: Insights from Online Discussions on GitHub Copilot
por: Ferreyra, Nicolás E. Díaz, et al.
Publicado: (2026)
por: Ferreyra, Nicolás E. Díaz, et al.
Publicado: (2026)
Software Supply Chain Smells: Lightweight Analysis for Secure Dependency Management
por: Schmid, Larissa, et al.
Publicado: (2026)
por: Schmid, Larissa, et al.
Publicado: (2026)
Dirty-Waters: Detecting Software Supply Chain Smells
por: Liu, Raphina, et al.
Publicado: (2024)
por: Liu, Raphina, et al.
Publicado: (2024)
SBOM.EXE: Countering Dynamic Code Injection based on Software Bill of Materials in Java
por: Sharma, Aman, et al.
Publicado: (2024)
por: Sharma, Aman, et al.
Publicado: (2024)
Automating the Detection of Code Vulnerabilities by Analyzing GitHub Issues
por: Cipollone, Daniele, et al.
Publicado: (2025)
por: Cipollone, Daniele, et al.
Publicado: (2025)
Maven-Hijack: Software Supply Chain Attack Exploiting Packaging Order
por: Reyes, Frank, et al.
Publicado: (2024)
por: Reyes, Frank, et al.
Publicado: (2024)
An Empirical Study of the Evolution of GitHub Actions Workflows
por: Mazrae, Pooya Rostami, et al.
Publicado: (2026)
por: Mazrae, Pooya Rostami, et al.
Publicado: (2026)
On the GitHub Actions Language: Usage, Evolution, and Workflow Reliability
por: Bardsiri, Aref Talebzadeh, et al.
Publicado: (2026)
por: Bardsiri, Aref Talebzadeh, et al.
Publicado: (2026)
Demystifying and Detecting Agentic Workflow Injection Vulnerabilities in GitHub Actions
por: Wang, Shenao, et al.
Publicado: (2026)
por: Wang, Shenao, et al.
Publicado: (2026)
An Empirical Study of Complexity, Heterogeneity, and Compliance of GitHub Actions Workflows
por: Abrokwah, Edward, et al.
Publicado: (2025)
por: Abrokwah, Edward, et al.
Publicado: (2025)
A Practical Solution to Systematically Monitor Inconsistencies in SBOM-based Vulnerability Scanners
por: Rosso, Martin, et al.
Publicado: (2025)
por: Rosso, Martin, et al.
Publicado: (2025)
Integrating Log-Based Security Analytics in Agile Workflows: A Real-World Experience Report
por: Thool, Arpit, et al.
Publicado: (2026)
por: Thool, Arpit, et al.
Publicado: (2026)
Reinforcement Learning-Driven Adaptation Chains: A Robust Framework for Multi-Cloud Workflow Security
por: Soveizi, Nafiseh, et al.
Publicado: (2025)
por: Soveizi, Nafiseh, et al.
Publicado: (2025)
Unlocking User-oriented Pages: Intention-driven Black-box Scanner for Real-world Web Applications
por: Wang, Weizhe, et al.
Publicado: (2025)
por: Wang, Weizhe, et al.
Publicado: (2025)
The Design Space of Lockfiles Across Package Managers
por: Gamage, Yogya, et al.
Publicado: (2025)
por: Gamage, Yogya, et al.
Publicado: (2025)
PROZE: Generating Parameterized Unit Tests Informed by Runtime Data
por: Tiwari, Deepika, et al.
Publicado: (2024)
por: Tiwari, Deepika, et al.
Publicado: (2024)
Automation and Reuse Practices in GitHub Actions Workflows: A Practitioner's Perspective
por: Delicheh, Hassan Onsori, et al.
Publicado: (2026)
por: Delicheh, Hassan Onsori, et al.
Publicado: (2026)
How Do Software Developers Use GitHub Actions to Automate Their Workflows?
por: Kinsman, Timothy, et al.
Publicado: (2021)
por: Kinsman, Timothy, et al.
Publicado: (2021)
The Hidden Costs of Automation: An Empirical Study on GitHub Actions Workflow Maintenance
por: Valenzuela-Toledo, Pablo, et al.
Publicado: (2024)
por: Valenzuela-Toledo, Pablo, et al.
Publicado: (2024)
Beyond the YAML File: Understanding Real-World GitHub Actions Workflow Adoption
por: Khatami, Ali, et al.
Publicado: (2026)
por: Khatami, Ali, et al.
Publicado: (2026)
Provenance of Adaptation in Scientific and Business Workflows -- Literature Review
por: Stage, Ludwig, et al.
Publicado: (2025)
por: Stage, Ludwig, et al.
Publicado: (2025)
Models Are Codes: Towards Measuring Malicious Code Poisoning Attacks on Pre-trained Model Hubs
por: Zhao, Jian, et al.
Publicado: (2024)
por: Zhao, Jian, et al.
Publicado: (2024)
FIKA: Expanding Dependency Reachability with Executability Guarantees
por: Gamage, Yogya, et al.
Publicado: (2026)
por: Gamage, Yogya, et al.
Publicado: (2026)
Software Bills of Materials in Maven Central
por: Gamage, Yogya, et al.
Publicado: (2025)
por: Gamage, Yogya, et al.
Publicado: (2025)
Guardrails as Infrastructure: Policy-First Control for Tool-Orchestrated Workflows
por: Sigdel, Akshey, et al.
Publicado: (2026)
por: Sigdel, Akshey, et al.
Publicado: (2026)
Ejemplares similares
-
On the effectiveness of Large Language Models for GitHub Workflows
por: Zhang, Xinyu, et al.
Publicado: (2024) -
Heimdallr: Characterizing and Detecting LLM-Induced Security Risks in GitHub CI Workflows
por: Ruan, Bonan, et al.
Publicado: (2026) -
Maven-Lockfile: High Integrity Rebuild of Past Java Releases
por: Schmid, Larissa, et al.
Publicado: (2025) -
Characterizing and Modeling the GitHub Security Advisories Review Pipeline
por: Segal, Claudio, et al.
Publicado: (2026) -
Can Highlighting Help GitHub Maintainers Track Security Fixes?
por: Liu, Xueqing, et al.
Publicado: (2024)