Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's limited to ghs_ (server to server token's), that have the new format enabled: https://github.blog/changelog/2026-04-24-notice-about-upcomi... (and actions that use the vulnerable package)

This include's the GITHUB_TOKEN that is builtin within a actions jobs.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: