heroui logo

GitHub Commits Skipping Workflows

Panther Rules

View Source
Summary
This detection rule is designed to identify GitHub commits that include workflow skipping directives, which can be utilized to bypass CI/CD processes and security checks. The key patterns monitored by this rule include: [skip ci], [ci skip], [no ci], [skip actions], [actions skip], and skip-checks:true. These patterns are particularly relevant in cross-fork scenarios where commits can be made to public and forkable repositories. When the rule is triggered, it suggests the possibility of intentional or unintentional security risks associated with bypassing automated workflows meant to enforce quality and security metrics. The alerts generated by this rule are limited to public repositories where forking is permitted, highlighting potential misuse in environments where open source collaboration is facilitated.
Categories
  • Cloud
  • Application
  • Identity Management
Data Sources
  • Web Credential
  • Process
  • Application Log
ATT&CK Techniques
  • T1195.002
  • T1622
Created: 2025-09-09