GitHub Actions have become a critical part of CI/CD pipelines, but do you really know what’s happening under the hood? This talk will break down GitHub Actions concepts, explore their security risks, and highlight how third-party actions in the supply chain can introduce vulnerabilities. We’ll examine real-world examples of misconfigurations, critical security risks, and unexpected workflow behaviors that attackers can exploit