Skip to main navigation Skip to search Skip to main content

Time for Actions: A Longitudinal Study of the GitHub Actions Marketplace

  • Stony Brook University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

GitHub Workflows have emerged as one of the most widely adopted CI/CD platforms, with millions of workflows integrated into modern software development. With the ability to encapsulate a subset of workflow functionality into reusable components known as GitHub Actions, any developer can publish their actions to the GitHub Actions Marketplace. To date, there has been no comprehensive analysis of the GitHub Actions Marketplace in terms of the number of actions, their growth over time, and their susceptibility to supply-chain attacks. In this paper, we present a longitudinal study of GitHub actions, aiming to better understand this important, modern software ecosystem. Over a period of four months, we collected and analyzed over 23K GitHub Actions including their source code as well as metadata about their creators. Our analysis investigates marketplace trends, identifies prevalent security issues in GitHub Actions, and characterizes novel attack vectors, including actions typosquatting and dangling remote references.

Original languageEnglish
Title of host publicationProceedings - 2025 IEEE Secure Development Conference, SecDev 2025
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages118-128
Number of pages11
ISBN (Electronic)9798331595951
DOIs
StatePublished - 2025
Event2025 IEEE Secure Development Conference, SecDev 2025 - Indianapolis, United States
Duration: Oct 14 2025Oct 16 2025

Publication series

NameProceedings - 2025 IEEE Secure Development Conference, SecDev 2025

Conference

Conference2025 IEEE Secure Development Conference, SecDev 2025
Country/TerritoryUnited States
CityIndianapolis
Period10/14/2510/16/25

Keywords

  • CI/CD
  • Github Actions
  • remote references

Fingerprint

Dive into the research topics of 'Time for Actions: A Longitudinal Study of the GitHub Actions Marketplace'. Together they form a unique fingerprint.

Cite this