Pipeline CI/CD seguro: commit a producción sin sustos
Como armar un pipeline CI/CD seguro con GitHub Actions, Docker y OIDC sin exponer secrets ni romper produccion. Guia 2026 con ejemplos reales
#cicd #githubactions #docker #kubernetes #oidc

Pipeline CI/CD seguro: commit a producción sin sustos
Como armar un pipeline CI/CD seguro con GitHub Actions, Docker y OIDC sin exponer secrets ni romper produccion. Guia 2026 con ejemplos reales
#cicd #githubactions #docker #kubernetes #oidc
Github Actionsでデプロイして環境変数が読み込めずUncaught Error: supabaseUrl is required.
A GitHub Actions workflow should be boring in the best possible way: predictable triggers, clear job names, useful logs, and failures that tell you what to fix. #GitHub #GitHubActions #DevOps
GitHub Actions just expanded data retention! Now checks, runs, and statuses are covered. This is genuinely useful for debugging flaky pipelines and tracking down old issues. Nice quality of life update. #GitHubActions #DevOps
GitHub Actions usage insights creep up across organizations, revealing workflow inefficiencies. A new tool enables org-wide visibility into CI health without manual workflow changes. 🛠️🔄 #GitHubActions #DevOps #CIHealth
The new Actions Runner Controller (ARC) v0.15.0 release just dropped! For anyone managing self-hosted GitHub Actions runners on Kubernetes, this is a useful update. Good to see the controller evolve. #GitHubActions #Kubernetes
GitHub Actionsにロックファイルが来るぞ #GitHubActions - Qiita qiita.com/access3151fq...
ふうん。自分のプロジェクトと同関係するか分からない
The honest bit from my refresher video:
My promotion workflow rebuilds artifacts from the tag instead of packaging once and promoting that exact build. It works. It's also not really promotion. Fixing it is on the list.
#CICD #GitHubActions
CVE-2026-44791 - n8n
An authenticated user with permission to create or modify workflows in n8n can bypass a security patch and potentially gain full control over the host. This can happen if users…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-44790 - n8n
An attacker with permission to create workflows in n8n can read sensitive files on the server. This could lead to a full server compromise if left unaddressed. To fix this,…
Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-44789 - n8n
An attacker with permission to edit workflows can exploit a weakness in n8n's HTTP Request node, potentially allowing them to execute malicious code on the instance. This issue…
Too many irrelevant or confusing CVEs? Use stackflag.com
Same builder, opposite structure
One project runs two separate pipelines. This one, Pegasus Galaxy, my browser + mobile game, runs one multi-stage GitHub Actions pipeline: parallel tests, three frontends, promotion across environments.
#CICD #GitHubActions
A CVSS 10 GeoServer Cloud vulnerability in a GitHub Actions workflow could have leaked repository secrets. No abuse found, and the workflow is gone.
#GeoServer #GeoServerCloud #GitHubActions #SupplyChainSecurity #CICD #DevSecOps #OpenSource #SecretsLeak
Need to deploy a .NET Web App on Azure Using GitHub Actions?
Check out this video with Phil here: https://www.youtube.com/watch?v=sCcNJy7KrZo
Cool #GithubActions trick~
If you're using a remote reusable workflow and want to use an action from that same remote repo, at the same commit, do this:
- uses: $/.github/actions/workflow-extra-action
Prepending the path with `$` does the trick 💚
Your GitHub Actions pipeline runs random Marketplace code with your secrets. pull_request_target makes it worse. Here's the autopsy:
#GitHubActions #DevSecOps #SupplyChain
GitHub Actionsの自動マージが、次のworkflowを起動しない ― 2ヶ月「直っていない」と思い込んでいたバグの正体
A "chore: bump dev tooling" PR quietly pulled in [email protected], a ReDoS. npm audit on main stayed green, so nobody caught it before merge. Dependency review gates block PRs https://www.valtersit.com/guides/ci_cd/dependency-review-gates-blocking-prs-with-cves/
#devsecops #githubactions #sca
CVE-2023-29199 - vm2
The vm2 library used in several GitHub Actions and rootio projects may let attackers run code they should not be able to. Updated versions have been released that fix this risk.…
Too many irrelevant or confusing CVEs? Use stackflag.com
CI should reduce uncertainty, not add ceremony. Keep the pipeline fast enough that developers trust it and small enough that failures point somewhere useful. #GitHubActions #DevOps #CICD