Briefing

WordPress Org Hardens GitHub Actions Workflows Against Supply‑Chain Attacks

security
by John Blackbourn · WordPress Gutenberg

Patch all WordPress org repositories by merging the hardening PRs, enabling Actionlint and Zizmor, and reviewing workflow permissions.

What to do now

Merge all hardening PRs, enable Actionlint and Zizmor scanning, and audit workflow permissions for each repo.

Summary

Recent supply‑chain attacks on GitHub Actions have highlighted the need for stricter workflow security, and the WordPress organization has responded with a comprehensive hardening program. Since January 2025, the wordpress‑develop repository has removed unsafe expressions, tightened permissions, and reduced credential persistence, while adding the Actionlint linter. In April 2025 the gutenberg repo received similar hardening and Actionlint integration. By June 2025, twenty unmaintained repos were archived to stop their Actions from running. April 2026 saw the introduction of the Zizmor static‑analysis tool and a GitHub Actions Workflow Standards handbook that flags common issues. In May 2026, multiple repos—including performance, two‑factor, and wporg‑main‑2022—were hardened to minimize permissions, and a reusable workflow used by dozens of repos was secured. The hardening effort also documented supply‑chain workflows as valid targets in the HackerOne bug‑bounty policy. The security team plans to enforce Actionlint and Zizmor scanning organization‑wide and to standardize a central SECURITY.md file.

Key changes

  • Removed unsafe expressions and tightened permissions in wordpress‑develop (Jan 2025).
  • Added Actionlint linter to wordpress‑develop and gutenberg (Jan & Apr 2025).
  • Archived twenty unmaintained repos to stop their Actions (June 2025).
  • Introduced Zizmor static‑analysis tool in wordpress‑develop (Apr 2026).
  • Published GitHub Actions Workflow Standards handbook (Apr 2026).
  • Hardened multiple repos in May 2026 to minimally scope permissions.
  • Secured reusable workflow used by dozens of repos (May 2026).
  • Documented supply‑chain workflows in HackerOne policy (May 2026).

Affects

wp-customers

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting