{"id":57608,"date":"2026-06-22T07:17:38","date_gmt":"2026-06-22T11:17:38","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=57608"},"modified":"2026-06-22T07:17:38","modified_gmt":"2026-06-22T11:17:38","slug":"github-actions-checkout-v7-pwn-request","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/github-actions-checkout-v7-pwn-request\/","title":{"rendered":"GitHub Actions Checkout v7 Blocks Malicious pull_request_target Workflows"},"content":{"rendered":"<p><a href=\"https:\/\/overcentral.com\/en\/vs-code-zero-day-steals-github-tokens-with-one-click\/\" title=\"VS Code zero-day steals GitHub tokens with one click\" data-iacss-internal=\"1\">GitHub<\/a> has released version 7 of its <strong><a href=\"https:\/\/github.com\/actions\/checkout\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">actions\/checkout<\/a><\/strong> action for GitHub Actions, introducing a critical security default that automatically blocks dangerous workflows exploiting the <code>pull_request_target<\/code>codecode event. This update directly addresses a long-standing attack vector, often called a &#8220;pwn request,&#8221; where untrusted code from a forked pull request can execute with full CI privileges, including access to the base repository\u2019s secrets, <code>GITHUB_TOKEN<\/code>codecode, and production resources. The new behavior, which will be backported to all supported major versions by July 2026, is designed to fail fast and prevent the most common patterns of this abuse.<\/p>\n<h2>Understanding the \u201cPwn Request\u201d Threat<\/h2>\n<p>The <code>pull_request_target<\/code>codecode event is one of the most frequently misused triggers in GitHub Actions. Unlike the standard <code>pull_request<\/code>codecode event, which runs with restricted permissions from the forked repository, <code>pull_request_target<\/code>codecode executes in the context of the base repository. This means it has full access to sensitive resources, such as deployment keys, cloud service credentials, and internal artifacts. When a maintainer checks out the head or merge commit of a pull request from an untrusted fork within this privileged context, the attacker&#8217;s code can run with those elevated permissions. This pattern has been responsible for multiple high-profile supply-chain compromises across the ecosystem.<\/p>\n<h2>What the GitHub Checkout v7 Update Blocks<\/h2>\n<p>The new <strong>actions\/checkout<\/strong> v7 update specifically refuses to fetch code from a forked pull request when used in <code>pull_request_target<\/code>codecode workflows or in <code>workflow_run<\/code>codecode jobs where the triggering event is a <code>pull_request*<\/code>codecode type. The action will fail if the <code>repository<\/code>codecode input resolves to the fork\u2019s repository, if the <code>ref<\/code>codecode matches <code>refs\/pull\/\/head<\/code>codecode or <code>refs\/pull\/\/merge<\/code>codecode, or if the <code>ref<\/code>codecode resolves to the fork pull request\u2019s head or merge commit SHA. This blocks common unsafe patterns like <code>refs\/pull\/${{ github.event.pull_request.number }}\/merge<\/code>codecode and <code>repository: ${{ github.event.pull_request.head.repo.full_name }}<\/code>codecode in privileged workflows.<\/p>\n<p>By failing early, the update prevents untrusted pull request code from reaching jobs that execute sensitive commands, such as <code>run: .\/scripts\/deploy.sh<\/code>codecode, which might have direct access to production secrets. However, GitHub has explicitly noted that this update does not claim to eliminate every variant of pwn requests. Workflows remain vulnerable if they manually pull and execute untrusted code using <code>run<\/code>codecode blocks that call <code>git<\/code>codecode or the <code>gh<\/code>codecode CLI to fetch arbitrary refs or repositories, as those operations bypass <code>actions\/checkout<\/code>codecode entirely.<\/p>\n<h2>How the Update Affects Existing Workflows<\/h2>\n<p>On July 16, 2026, GitHub will backport this enforcement logic into all currently supported major versions of the action. This means workflows pinned to floating tags like <code>actions\/checkout@v4<\/code>codecode will automatically inherit the safer defaults without any manual change. Pipelines that pin <code>actions\/checkout<\/code>codecode to a specific SHA, minor, or patch version will not be updated automatically and must be upgraded via Dependabot or established internal processes to benefit from the new protections.<\/p>\n<p>Same-repository pull requests are unaffected by this change. The traditional <code>pull_request<\/code>codecode event behavior remains unchanged, ensuring that standard contribution workflows continue as usual. The update is focused on the most prevalent misuse of the <code>pull_request_target<\/code>codecode event, but GitHub may expand hardening to additional event types, such as <code>issue_comment<\/code>codecode, in the future.<\/p>\n<h2>Opt-Out Path for Legitimate Use Cases<\/h2>\n<p>For scenarios where a fork\u2019s pull request code must legitimately run with elevated trust\u2014for example, coverage generation using private artifact registries or authenticated checks on incoming changes\u2014GitHub provides an explicit opt-out path. After reviewing the official guidance on securely using <code>pull_request_target<\/code>codecode, maintainers can add the <code>allow-unsafe-pr-checkout<\/code>codecode input to the <code>actions\/checkout<\/code>codecode step to re-enable fork PR checkouts in these workflows. The input name is intentionally loud and descriptive to ensure its presence is obvious during code review and static analysis, reinforcing that turning off the default protection is a conscious, high-impact security decision.<\/p>\n<h2>What Affected Users Should Do Now<\/h2>\n<p>Security-focused teams are encouraged to adopt a defense-in-depth approach. For most workflows, the recommended practice is to run untrusted fork code under the <code>pull_request<\/code>codecode event with restricted permissions, reserving <code>pull_request_target<\/code>codecode and any unsafe checkouts only for carefully audited pipelines that genuinely require access to secrets and sensitive resources. Developers should immediately review any workflows using <code>actions\/checkout<\/code>codecode with a <code>pull_request_target<\/code>codecode trigger, identify any patterns that explicitly fetch fork PR refs or repositories, and either upgrade to v7 or update the input to include the safe defaults. For teams using pinned versions, a proactive update via Dependabot is the most straightforward path to securing their pipelines against this class of attack.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>GitHub has released version 7 of its actions\/checkout action for GitHub Actions, introducing a critical security default that automatically blocks dangerous workflows exploiting the pull_request_targetcodecode event. This update directly addresses a long-standing attack vector, often called a &#8220;pwn request,&#8221; where untrusted code from a forked pull request can execute with full CI privileges, including access [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":85303,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/57608.png","fifu_image_alt":"GitHub Actions Checkout v7 Blocks Malicious pull_request_target Workflows","footnotes":""},"categories":[349],"tags":[],"class_list":["post-57608","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/57608.png","fifu_image_alt":"GitHub Actions Checkout v7 Blocks Malicious pull_request_target Workflows","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/57608","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=57608"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/57608\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/85303"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=57608"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=57608"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=57608"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}