# How to catch GitHub Actions workflow injections before attackers do

> Quelle: GitHub Security Advisories — https://github.blog/security/vulnerability-research/how-to-catch-github-actions-workflow-injections-before-attackers-do/

## Maßnahmen

- [ ] Betroffenheit im eigenen Stack prüfen: Versionen/Komponenten abgleichen.
- [ ] Originalquelle / Hersteller-Advisory lesen: https://github.blog/security/vulnerability-research/how-to-catch-github-actions-workflow-injections-before-attackers-do/
- [ ] Verfügbaren Patch oder Workaround einspielen und dokumentieren.
