[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fZj0NBMrYazx7g0c-QkR5H2Y5NytofeW7sbyvgG9ICDE":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"c8e7e05b-b395-41c4-91d1-d7f9c6693475","github-actions-introduces-cache-mode-to-mitigate-cache-poisoning-in-cicd-pipelines","aca046c2-fda9-4ffe-899e-553144770ca4","GitHub Actions Introduces Cache-Mode to Mitigate Cache Poisoning in CI\u002FCD Pipelines","Cache poisoning attacks in CI\u002FCD pipelines allow adversaries to inject malicious artifacts into shared build caches, which are then unknowingly consumed by subsequent workflow jobs — as seen in the Ultralytics PyPI and TanStack npm supply chain compromises. The root issue stems from insufficient access controls and configuration defaults that permit untrusted workflows to write to shared caches, creating a vector for software supply chain attacks. GitHub's new 'cache-mode' setting is a critical configuration hardening measure, but its value is only realized when developers actively adopt and configure it correctly. This incident highlights how CI\u002FCD infrastructure, often treated as a development convenience rather than a security boundary, is an increasingly attractive target for threat actors seeking to poison software at the build stage.","**Immediate actions:**\n- Enable and configure the new GitHub Actions `cache-mode` setting in all existing workflows to restrict untrusted write access to the Actions cache.\n- Audit current CI\u002FCD pipeline cache configurations to identify workflows that permit cross-job or cross-fork cache writes.\n- Pin all third-party GitHub Actions to a specific commit SHA rather than a mutable tag to prevent dependency substitution.\n\n**Long-term improvements:**\n- Adopt a principle of least privilege for CI\u002FCD pipeline permissions, granting only the minimum required scopes to tokens and workflows.\n- Implement a formal Software Supply Chain security policy that includes regular review of all build dependencies, caching strategies, and third-party actions.\n- Integrate Software Composition Analysis (SCA) tools into pipelines to automatically detect tampered or unexpected build artifacts before deployment.\n\n**Detection measures:**\n- Enable detailed audit logging for all GitHub Actions workflow runs and cache interactions, and forward logs to a centralized SIEM for anomaly detection.\n- Set up alerting for unexpected changes in build artifact hashes or checksums to detect potential cache poisoning attempts early.\n- Monitor public threat intelligence feeds for newly disclosed CI\u002FCD and package registry supply chain compromises affecting your dependency ecosystem.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 16: Application Software Security","NIST SP 800-218 (SSDF) PW.4: Reuse Existing, Well-Secured Software","NIST SP 800-218 (SSDF) RV.1: Identify and Confirm Vulnerabilities","NIST SP 800-161r1: Supply Chain Risk Management","NIST CSF DE.CM-3: Personnel Activity Monitoring","SLSA Supply Chain Levels for Software Artifacts (L2\u002FL3 Build Integrity)","OpenSSF Scorecard: Token-Permissions and Pinned-Dependencies checks","ITIL Change Management: Controlled pipeline configuration change processes","published","2026-09-16T22:21:14.22243+00:00","2026-09-16T22:21:13.922+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fsocket.dev\u002Fblog\u002Fgithub-actions-cache-mode?utm_medium=feed","github-actions-adds-cache-mode-to-limit-cache-poisoning-risk-d65f1f","GitHub Actions Adds cache-mode to Limit Cache Poisoning Risk",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":37,"name":38,"slug":39,"description":40,"color":41},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]