GitHub Actions issued GitHub_TOKEN disclosure in GitHub Actions logs
Summary
A security vulnerability in GitHub Actions led to the disclosure of GitHub_TOKEN in logs, potentially exposing credentials.
View Cached Full Text
Cached at: 05/13/26, 09:16 PM
composer/composer
Source: https://github.com/composer/composer
Dependency Management for PHP
Composer helps you declare, manage, and install dependencies of PHP projects.
See https://getcomposer.org/ for more information and documentation.
Installation / Usage
Download and install Composer by following the official instructions.
For usage, see the documentation.
Packages
Find public packages on Packagist.org.
For private package hosting take a look at Private Packagist.
Community
Follow @packagist or @seldaek on X for announcements, or check the #composerphp hashtag.
For support, Stack Overflow offers a good collection of Composer related questions, or you can use the GitHub discussions.
Please note that this project is released with a Contributor Code of Conduct. By participating in this project and its community you agree to abide by those terms.
Requirements
Latest Composer
PHP 7.2.5 or above for the latest version.
Composer 2.2 LTS (Long Term Support)
PHP versions 5.3.2 - 8.1 are still supported via the LTS releases of Composer (2.2.x). If you
run the installer or the self-update command the appropriate Composer version for your PHP
should be automatically selected.
Binary dependencies
unzip(or7z/7zz)gziptarunrarxz- Git (
git) - Mercurial (
hg) - Fossil (
fossil) - Perforce (
p4) - Subversion (
svn)
The need for these binary dependencies may vary depending on individual use cases. For most users,
only 2 dependencies are essential for Composer: unzip (or 7z/7zz), and git. If the
ext-zip extension is available, only git
is needed, but this is not recommended.
Authors
- Nils Adermann | GitHub | X | [email protected] | naderman.de
- Jordi Boggiano | GitHub | X | [email protected] | seld.be
See also the list of contributors who participated in this project.
Security Reports
Please send any sensitive issue to [email protected]. Thanks!
License
Composer is licensed under the MIT License - see the LICENSE file for details.
Acknowledgments
- This project’s Solver started out as a PHP port of openSUSE’s Libzypp satsolver.
Similar Articles
GitHub Actions default configs from Anthropic, Google, and OpenAI's own coding agents were all vulnerable to the same RCE
Security researchers discovered critical vulnerabilities in the default GitHub Actions configurations for Anthropic's Claude Code, Google's Gemini CLI, and OpenAI's Codex, allowing remote code execution through unauthenticated issues. A related privilege escalation flaw in Google's ADK repo highlights systemic weaknesses in the CI/CD scaffolding for these AI agents.
GitLost: We Tricked GitHub's AI Agent into Leaking Private Repos
Noma Labs discovered a critical prompt injection vulnerability in GitHub's Agentic Workflows, allowing unauthenticated attackers to exfiltrate data from private repositories by posting a crafted GitHub issue in a public repository of the same organization.
My security camera shipped a GitHub admin token in its login page
A security researcher discovered that Hanwha security cameras ship firmware containing a GitHub admin token, exposed in the camera's login page due to a build process that embeds the entire CI environment into the UI code.
Full Disclosure: 1-Click GitHub Token Stealing via a VSCode Bug
A security researcher discloses a critical vulnerability in VSCode's webview that allows attackers to steal full-access GitHub OAuth tokens by luring users to click a link. The bug affects the github.dev web editor.
GitHub Actions needs OIDC audience constraints
This blog post argues that GitHub Actions lacks static OIDC audience constraints, unlike GitLab CI/CD, and that this design weakness poses an increasing security risk as OIDC-based federation becomes more common.