#githubaction
It's the little things

Like being able to make #Music with #PowerShell in a #GitHubAction, at 5x realtime.

GitHub workflow runners are quicker than you'd think.

And Making Music in a GitHub Workflow is beautifully batty.
September 16, 2026 at 10:31 PM
每小时往固定文件追加一行运行日志,我想不明白这种垃圾项目有任何存在的意义。

https://github.com/jowelrana120/hentai-daily-crawler/blob/main/.github/workflows/zPuwtNMToNHB.yml #chore #githubaction #abuse
August 19, 2026 at 12:33 PM
GitHub Actions for Python Projects A Practical Guide to CI/CD Automation: Automating Testing, Building & Deployment by AhmedAdawy is a new release on Leanpub!

Master automated workflows for your Python code with … leanpub.com/githubaction...
August 9, 2026 at 2:45 AM
意図したとおりに動いているのでv2.1完了ってカンジかな?
あとは手動でしばらく動かして問題なければGithubActionに渡して自動化BOT完成だ
August 7, 2026 at 9:18 AM
MCPサーバーは“信用して置く”時代じゃない。セキュリティ監査のやり方を考える
https://papoo.work/doc/9391c69130db4861
#mcp #ai #セキュリティ #githubaction #静的解析
MCPサーバーは“信用して置く”時代じゃない。セキュリティ監査のやり方を考える
papoo.work
August 6, 2026 at 1:03 PM
MCPサーバーは“信用して置く”時代じゃない。セキュリティ監査のやり方を考える
https://papoo.work/doc/9391c69130db4861
#mcp #ai #セキュリティ #githubaction #静的解析
MCPサーバーは“信用して置く”時代じゃない。セキュリティ監査のやり方を考える
papoo.work
August 5, 2026 at 9:13 PM
MCPサーバーは“信用して置く”時代じゃない。セキュリティ監査のやり方を考える
https://papoo.work/doc/9391c69130db4861
#mcp #ai #セキュリティ #githubaction #静的解析
MCPサーバーは“信用して置く”時代じゃない。セキュリティ監査のやり方を考える
papoo.work
August 5, 2026 at 12:55 PM
MCPサーバーは“信用して置く”時代じゃない。セキュリティ監査のやり方を考える
https://papoo.work/doc/9391c69130db4861
#mcp #ai #セキュリティ #githubaction #静的解析
MCPサーバーは“信用して置く”時代じゃない。セキュリティ監査のやり方を考える
papoo.work
August 5, 2026 at 12:40 PM
MCPサーバーは“信用して置く”時代じゃない。セキュリティ監査のやり方を考える
https://papoo.work/doc/9391c69130db4861
#mcp #ai #セキュリティ #githubaction #静的解析
MCPサーバーは“信用して置く”時代じゃない。セキュリティ監査のやり方を考える
papoo.work
August 5, 2026 at 11:25 AM
これでしばらく動かして問題なかったらGithubActionってところでBOTとして自動化できるっぽいんだけど…よくわからんのでこれも帰ったらいろいろ調べんとな…
August 4, 2026 at 8:37 PM
MCPサーバーは“信用して置く”時代じゃない。セキュリティ監査のやり方を考える
https://papoo.work/doc/9391c69130db4861
#mcp #ai #セキュリティ #githubaction #静的解析
MCPサーバーは“信用して置く”時代じゃない。セキュリティ監査のやり方を考える
papoo.work
August 3, 2026 at 2:39 AM
MCPサーバーは“信用して置く”時代じゃない。セキュリティ監査のやり方を考える
https://papoo.work/doc/9391c69130db4861
#mcp #ai #セキュリティ #githubaction #静的解析
MCPサーバーは“信用して置く”時代じゃない。セキュリティ監査のやり方を考える
papoo.work
August 2, 2026 at 7:37 PM
MCPサーバーは“信用して置く”時代じゃない。セキュリティ監査のやり方を考える
https://papoo.work/doc/9391c69130db4861
#mcp #ai #セキュリティ #githubaction #静的解析
MCPサーバーは“信用して置く”時代じゃない。セキュリティ監査のやり方を考える
papoo.work
August 2, 2026 at 6:04 AM
MCPサーバーは“信用して置く”時代じゃない。セキュリティ監査のやり方を考える
https://papoo.work/doc/9391c69130db4861
#mcp #ai #セキュリティ #githubaction #静的解析
MCPサーバーは“信用して置く”時代じゃない。セキュリティ監査のやり方を考える
papoo.work
August 1, 2026 at 11:13 AM
MCPサーバーは“信用して置く”時代じゃない。セキュリティ監査のやり方を考える
https://papoo.work/doc/9391c69130db4861
#mcp #ai #セキュリティ #githubaction #静的解析
MCPサーバーは“信用して置く”時代じゃない。セキュリティ監査のやり方を考える
papoo.work
July 31, 2026 at 8:09 PM
MCPサーバーは“信用して置く”時代じゃない。セキュリティ監査のやり方を考える
https://papoo.work/doc/9391c69130db4861
#mcp #ai #セキュリティ #githubaction #静的解析
MCPサーバーは“信用して置く”時代じゃない。セキュリティ監査のやり方を考える
papoo.work
July 31, 2026 at 7:39 PM
最近までGitHubPageって何となく静的サイトのイメージだった

よくよく考えると、JSでDBのやり取りが動的に出来るし、既にあるリポジトリに対しての定期処理を行うのはGitHubActionから出来る。しかもLinux環境を簡単に用意してるからbashやPythonを実行するのも多分出来そう

AtCoderProblemsはサーバーサイドの技術が大きいと思うけど、GitHubPageで動く簡易サイトは作れそうな気がする
May 26, 2026 at 8:35 AM
Popular GitHub Action Tags Redirected to Imposter Commit to Steal CI/CD Credentials reconbee.com/popular-gith...

#GitHubaction #CICDcredentials #potatosecurity #potatoattack
May 19, 2026 at 1:16 PM
GitHubActionの制限がきつくなる未来あるのかなぁ、個人開発組はしんどくなりそう
May 16, 2026 at 4:52 AM
84 npm packages in the TanStack namespace were compromised with credential-stealing payloads targeting GitHub Actions and CI systems, part of the Mini Shai-Hulud supply-chain attack, affecting millions of downloads. #TanStack #MiniShaiHulud #npm
TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud...
Socket researchers found a compromise in 84 npm package artifacts under the TanStack namespace that inserted a credential-stealing payload targeting GitHub Actions and other CI systems, with some malicious versions reaching more than 12 million weekly downloads. The campaign is tied to the Mini Shai-Hulud supply-chain operation and includes a malicious optional dependency, code execution during installation, and exfiltration over the Session infrastructure. #TanStack #MiniShaiHulud #GitHubActions #Session #npm
www.hendryadrian.com
May 12, 2026 at 12:30 AM
Actually, one more thing:

I _strongly_ prefer #YAML pipelines are as simple as possible.

IMO, they should just be a #PowerShell script that uses the environment variables.

Or a call to another #GitHubAction

Do this to improve your #GitHubWorkflows.
May 10, 2026 at 9:59 PM
呪文にしか聞こえないだろうけど、書くと。
・VSCodeでClaudeCodeを使用
・ClaudeCodeをAutoで運用
・GitHubの設定をして、CopilotとGeminiをReviewerに設定
・ClaudeCodeは常にbranch作成させ、作業させて、PR作成
・PRをReviewerが指摘したものを、俺は「PR # N の対応して」と指示すると、ClaudeCodeが可否を含めて最新情報を確認して、必要に応じて修正・コメントする
・GitHubActionにCI設定し、Greenにならないと、俺がPR承認しない
となっています。どうして。
May 3, 2026 at 7:45 AM
My head of ops complained that #GitHub CI/CD has become _so_ unreliable, specifically #githubaction s and its scheduler (even with #selfhosted runners) that we need to migrate to an alternative.

We're not alone, see e.g. #zig […]

[Original post on mastodon.habets.dev]
March 8, 2026 at 8:12 PM