Dangerous branch names
Story that explains the dangers of using the name of a branch in a workflow that uses pull_request_target.
Blogpost / 07-19-2026
Netherlands
Dirk is a maintainer of various open source projects where ImageMagick is the most well known. Since 2013 he has been working on this project and improved the experience for the Windows users of this project. And also created a C# library to make it possible to use ImageMagick in .NET. In 2015 he moved the project to GitHub and then helped GitHub as an early tester of new features.
Story that explains the dangers of using the name of a branch in a workflow that uses pull_request_target.
Blogpost / 07-19-2026
Story about how I could have used the knowledge about insecure GitHub actions workflows to compromise several millions of installations of a popular editor extension
Blogpost / 03-11-2026
Story about what we learned for the ImageMagick project from training of the GitHub Secure Open Source Fund.
Blogpost / 02-17-2026
Story about using NuGet Trusted Publishing together with Artifact Signing.
Blogpost / 01-12-2026
A story of exploiting PR comment handling in GitHub Actions to achieve command execution, followed by disclosure, remediation, and practical workflow hardening guidance.
Blogpost / 11-21-2025
Story about how I used Trusted Publisher of npm to publish the ImageMagick WASM library without PAT tokens.
Blogpost / 11-03-2025
Added support for Trusted Signing to the Sign CLI.
Open source project / 09-17-2024
Story how I am signing NuGet packages on GitHub with an Azure Trusted Signing certificate.
Blogpost / 07-01-2024