GitHub Actions issued GitHub_TOKEN disclosure in GitHub Actions logs

Hacker News Top News

Summary

A security vulnerability in GitHub Actions led to the disclosure of GitHub_TOKEN in logs, potentially exposing credentials.

No content available
Original Article
View Cached Full Text

Cached at: 05/13/26, 09:16 PM

composer/composer

Source: https://github.com/composer/composer

Composer

Dependency Management for PHP

Composer helps you declare, manage, and install dependencies of PHP projects.

See https://getcomposer.org/ for more information and documentation.

Continuous Integration

Installation / Usage

Download and install Composer by following the official instructions.

For usage, see the documentation.

Packages

Find public packages on Packagist.org.

For private package hosting take a look at Private Packagist.

Community

Follow @packagist or @seldaek on X for announcements, or check the #composerphp hashtag.

For support, Stack Overflow offers a good collection of Composer related questions, or you can use the GitHub discussions.

Please note that this project is released with a Contributor Code of Conduct. By participating in this project and its community you agree to abide by those terms.

Requirements

Latest Composer

PHP 7.2.5 or above for the latest version.

Composer 2.2 LTS (Long Term Support)

PHP versions 5.3.2 - 8.1 are still supported via the LTS releases of Composer (2.2.x). If you run the installer or the self-update command the appropriate Composer version for your PHP should be automatically selected.

Binary dependencies

  • unzip (or 7z/7zz)
  • gzip
  • tar
  • unrar
  • xz
  • Git (git)
  • Mercurial (hg)
  • Fossil (fossil)
  • Perforce (p4)
  • Subversion (svn)

The need for these binary dependencies may vary depending on individual use cases. For most users, only 2 dependencies are essential for Composer: unzip (or 7z/7zz), and git. If the ext-zip extension is available, only git is needed, but this is not recommended.

Authors

See also the list of contributors who participated in this project.

Security Reports

Please send any sensitive issue to [email protected]. Thanks!

License

Composer is licensed under the MIT License - see the LICENSE file for details.

Acknowledgments

  • This project’s Solver started out as a PHP port of openSUSE’s Libzypp satsolver.

Similar Articles

GitHub Actions default configs from Anthropic, Google, and OpenAI's own coding agents were all vulnerable to the same RCE

Reddit r/artificial

Security researchers discovered critical vulnerabilities in the default GitHub Actions configurations for Anthropic's Claude Code, Google's Gemini CLI, and OpenAI's Codex, allowing remote code execution through unauthenticated issues. A related privilege escalation flaw in Google's ADK repo highlights systemic weaknesses in the CI/CD scaffolding for these AI agents.

GitLost: We Tricked GitHub's AI Agent into Leaking Private Repos

Hacker News Top

Noma Labs discovered a critical prompt injection vulnerability in GitHub's Agentic Workflows, allowing unauthenticated attackers to exfiltrate data from private repositories by posting a crafted GitHub issue in a public repository of the same organization.

GitHub Actions needs OIDC audience constraints

Lobsters Hottest

This blog post argues that GitHub Actions lacks static OIDC audience constraints, unlike GitLab CI/CD, and that this design weakness poses an increasing security risk as OIDC-based federation becomes more common.